Description
In the Linux kernel, the following vulnerability has been resolved:

drm/sun4i: crtc: Propagate layer initialization error

sun4i_crtc_init() returns plain NULL when layer initialization fails,
while all its other error paths return an error pointer. The only
caller, sun4i_tcon_bind(), checks the result with IS_ERR() and happily
continues with tcon->crtc set to NULL. sun4i_rgb_init() and
sun4i_lvds_init() then dereference it in drm_crtc_mask(), which
oopses.

Return the error pointer instead.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel crash
Action: Patch immediately
AI Analysis

Impact

The vulnerability resides in the DRM driver for the sun4i CRTC in the Linux kernel. In sun4i_crtc_init the function returns a plain NULL when layer initialization fails, while all other error paths return an error pointer. The caller, sun4i_tcon_bind, checks the result with IS_ERR and incorrectly treats NULL as handled, setting tcon->crtc to NULL. Later calls such as sun4i_rgb_init or sun4i_lvds_init dereference this NULL pointer in drm_crtc_mask(), causing a kernel oops and crash. This is a classic null‑pointer dereference (CWE‑476) and gives an attacker the possibility to trigger a denial of service by crashing the kernel.

Affected Systems

The flaw affects all Linux kernel builds that contain the sun4i DRM driver before the patch. It applies to any distribution that includes this driver as part of the kernel. The exact affected releases are not listed, so any kernel incorporating the unpatched sun4i_crtc_init code is at risk.

Risk and Exploitability

The EPSS score is reported as < 1%, indicating a very low probability of exploitation at the time of this advisory, and the vulnerability is not listed in CISA's KEV catalog. The attack likely requires local or privileged access, such as supplying malformed DRM inputs or interacting with the device during initialization. Because the flaw does not expose an externally reachable code path, remote exploitation is unlikely, but a local attacker with discretionary access to the DRM subsystem could force a crash, leading to downtime. Overall the risk is modest but non‑negligible; patching removes the weakness entirely.

Generated by OpenCVE AI on September 20, 2026 at 00:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel update that includes the fix to sun4i_crtc_init.
  • Restrict access to the DRM device by setting appropriate permissions or configuring SELinux policies to limit operations to trusted users or services.
  • If the sun4i DRM driver is not required for the workload, disable it in kernel configuration or via modprobe blacklisting.

Generated by OpenCVE AI on September 20, 2026 at 00:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/sun4i: crtc: Propagate layer initialization error sun4i_crtc_init() returns plain NULL when layer initialization fails, while all its other error paths return an error pointer. The only caller, sun4i_tcon_bind(), checks the result with IS_ERR() and happily continues with tcon->crtc set to NULL. sun4i_rgb_init() and sun4i_lvds_init() then dereference it in drm_crtc_mask(), which oopses. Return the error pointer instead.
Title drm/sun4i: crtc: Propagate layer initialization error
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:22.594Z

Reserved: 2026-09-11T19:38:34.799Z

Link: CVE-2026-90297

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:27.137

Modified: 2026-09-17T17:17:27.137

Link: CVE-2026-90297

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:30:16Z

Weaknesses