Description
In the Linux kernel, the following vulnerability has been resolved:

drm/msm: Fix task_struct reference leak in recover_worker

get_pid_task() increments the task reference count, but the
corresponding put_task_struct() was missing in the else branch,
leaking a reference on every GPU hang recovery.

Patchwork: https://patchwork.freedesktop.org/patch/730662/
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Resource Leak Leading to Denial of Service
Action: Apply Patch
AI Analysis

Impact

The Linux kernel has a flaw in the drm/msm module where the recover_worker function increments a task reference count via get_pid_task() but fails to release it in the else branch, causing a reference leak for every GPU hang recovery. This leak results in unchecked kernel memory consumption, potentially exhausting system resources and degrading kernel stability. The weakness is a classic Resource Management Flaw and can lead to a denial of service if numerous GPU hang recoveries occur.

Affected Systems

All Linux kernel installations that include the drm/msm driver and have not applied the fix referenced in the patch repo. The vulnerability is present in the mainline kernel and any derivative kernels that have not integrated the commit that added the missing put_task_struct() call. No explicit version numbers are supplied, so any kernel build from sources that predates the fix is affected.

Risk and Exploitability

The EPSS score is reported as less than 1%, indicating a very low probability of exploitation. The vulnerability is not included in the CISA KEV catalog, and no CVSS score is provided; however, the potential for resource exhaustion suggests a high impact if triggered repeatedly. The attack vector likely requires repeated GPU hang events to accumulate the leaks, implying a localized or system‑level DoS rather than immediate remote code execution. Because the exploit requires the kernel to be in a state where GPU hangs occur, operational circumstances and denial of service are the primary concerns.

Generated by OpenCVE AI on September 19, 2026 at 06:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release that includes the 40b793714ad8 commit that restores the missing put_task_struct() call.
  • If a kernel upgrade is not feasible, manually backport the patch from the kernel repository to the current kernel source and rebuild the kernel.
  • To mitigate temporary risk, tune the GPU driver or system configuration to limit the frequency of GPU hang recovery cycles or monitor kernel memory usage for signs of excessive task_struct references.

Generated by OpenCVE AI on September 19, 2026 at 06:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-399

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix task_struct reference leak in recover_worker get_pid_task() increments the task reference count, but the corresponding put_task_struct() was missing in the else branch, leaking a reference on every GPU hang recovery. Patchwork: https://patchwork.freedesktop.org/patch/730662/
Title drm/msm: Fix task_struct reference leak in recover_worker
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:46.457Z

Reserved: 2026-09-17T15:57:05.659Z

Link: CVE-2026-93059

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:59.550

Modified: 2026-09-17T17:17:59.550

Link: CVE-2026-93059

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T13:15:16Z

Weaknesses