Description
In the Linux kernel, the following vulnerability has been resolved:

drm/msm: Only fini scheduler after successful init

msm_ringbuffer_new() destroys a partially initialized ring through
msm_ringbuffer_destroy() when an allocation or scheduler setup step
fails.

If drm_sched_init() fails before it finishes initializing the scheduler,
the failure path still calls drm_sched_fini(). That teardown path assumes
the scheduler work items, lists, and workqueue state were initialized.

Track successful scheduler initialization and call drm_sched_fini() only
after drm_sched_init() returned 0.

This issue was found by a static analysis checker and confirmed by
manual source review.

Patchwork: https://patchwork.freedesktop.org/patch/738905/
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (crash)
Action: Patch Now
AI Analysis

Impact

When the DRM MSM scheduler initialization fails, the cleanup path incorrectly calls drm_sched_fini on partially initialized resources, leading to a kernel crash. The bug was uncovered by static analysis and confirmed by source review and results in an abrupt termination of the system or module, compromising availability. The vulnerability does not provide a remote control path and is limited to the system that loads the affected module.

Affected Systems

The flaw exists in the Linux kernel’s DRM MSM component. All kernel releases that ship the drm/msm module carry the risk if the module fails to initialize. No specific version numbers are listed in the advisory, so any kernel version that includes this code path is potentially vulnerable.

Risk and Exploitability

No CVSS score is supplied; however, the EPSS score is below 1% and it is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation. Attackers would need to trigger a module load failure or a system boot scenario that paths the faulty cleanup, which is a local‑only vector. The impact is denial of service rather than code execution or privilege escalation.

Generated by OpenCVE AI on September 19, 2026 at 06:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a kernel version that includes the patch for improper scheduler cleanup in drm/msm
  • If the module is not required, disable or unload drm/msm to avoid the failure path
  • Monitor kernel logs for 'drm_sched_fini' crashes and apply the fix promptly

Generated by OpenCVE AI on September 19, 2026 at 06:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
CWE-665

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/msm: Only fini scheduler after successful init msm_ringbuffer_new() destroys a partially initialized ring through msm_ringbuffer_destroy() when an allocation or scheduler setup step fails. If drm_sched_init() fails before it finishes initializing the scheduler, the failure path still calls drm_sched_fini(). That teardown path assumes the scheduler work items, lists, and workqueue state were initialized. Track successful scheduler initialization and call drm_sched_fini() only after drm_sched_init() returned 0. This issue was found by a static analysis checker and confirmed by manual source review. Patchwork: https://patchwork.freedesktop.org/patch/738905/
Title drm/msm: Only fini scheduler after successful init
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:45.793Z

Reserved: 2026-09-17T15:57:05.659Z

Link: CVE-2026-93058

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:59.430

Modified: 2026-09-17T17:17:59.430

Link: CVE-2026-93058

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T13:15:16Z

Weaknesses