Description
In the Linux kernel, the following vulnerability has been resolved:

drm/omap: dsi: Do not copy isr table

To be able to unregister stuff from isrs, the corresponding table was
copied. Nobody seems to unregister stuff that way, so it does not help.
But there are stack-allocated objects passed to these isrs giving chances
of UAF of these objects if irqs are unregistered while they are handled,
so better do not copy that table.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free that can corrupt kernel memory
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel DRM OMAP DSI driver previously created a copy of its interrupt service routine table to enable the unregistration of interrupts. Because the copied table referenced stack‑allocated objects used by the ISRs, an IRQ could be unregistered while an ISR was still executing; if the stack objects were freed in that window, a use‑after‑free condition would arise. This kernel memory corruption could lead to a kernel panic or give a local attacker the ability to execute arbitrary code with elevated privileges.

Affected Systems

All Linux kernel releases containing the DRM OMAP DSI driver before the patch that removes the ISR table copy are affected. The vulnerability applies to generic Linux systems running the kernel, with no specific vendor or version range limits beyond the inclusion of the affected driver.

Risk and Exploitability

The CVSS score of 7.8 classifies this flaw as high severity, while the EPSS score of less than 1% suggests a very low current exploitation probability. It is not listed in the CISA KEV catalog. The likely attack vector is a local user with sufficient privileges to manipulate IRQ registration, such as a system administrator or compromised privileged process, triggering the fault during ongoing ISR activity.

Generated by OpenCVE AI on September 19, 2026 at 15:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel update that removes the copied ISR table.
  • If an update cannot be applied immediately, unload or disable the DRM OMAP DSI driver to eliminate the vulnerable code path.
  • As a temporary measure, avoid operations that frequently unregister interrupts on affected hardware, thereby reducing the chance that an ISR is still running when it is removed.

Generated by OpenCVE AI on September 19, 2026 at 15:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/omap: dsi: Do not copy isr table To be able to unregister stuff from isrs, the corresponding table was copied. Nobody seems to unregister stuff that way, so it does not help. But there are stack-allocated objects passed to these isrs giving chances of UAF of these objects if irqs are unregistered while they are handled, so better do not copy that table.
Title drm/omap: dsi: Do not copy isr table
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:31.233Z

Reserved: 2026-09-11T19:38:34.801Z

Link: CVE-2026-90316

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:29.443

Modified: 2026-09-18T18:17:53.277

Link: CVE-2026-90316

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:45:16Z

Weaknesses