Description
In the Linux kernel, the following vulnerability has been resolved:

drm/msm/adreno: fix use after free on error path in a6xx_gpu_init()

The a6xx_destroy() function frees "a6xx_gpu" and so "adreno_gpu" points
to freed memory. Preserve the error code before freeing the memory to
avoid a use after free.

Patchwork: https://patchwork.freedesktop.org/patch/732275/
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption
Action: Apply patch
AI Analysis

Impact

A use‑after‑free flaw exists in the a6xx_gpu_init function of the drm/msm/adreno DRM driver. When the initialization fails, the driver frees the a6xx_gpu structure while the adreno_gpu pointer still references the now‑freed memory. If an attacker can exercise this error path before the memory is reused, the dangling pointer may be used to read or overwrite data in the freed area, leading to kernel memory corruption that could crash the system or serve as a foothold for privilege escalation. The weakness is identified as CWE‑416.

Affected Systems

The vulnerability affects Linux kernel installations that include the Adreno DRM driver for Adreno GPUs, specifically the drm/msm/adreno module. All kernel builds that contain the a6xx_gpu_init initialization logic are potentially affected; no specific version range is given in the advisory.

Risk and Exploitability

The EPSS score is reported as less than 1 %, indicating a very low likelihood of exploitation as of this analysis. The vulnerability is not listed in CISA KEV, and no active exploitation has been documented. The attack would likely require local or privileged access to trigger the driver’s error path during GPU initialization. The use‑after‑free can cause kernel memory corruption and, if an attacker can influence the contents of the freed memory, could lead to arbitrary kernel code execution. However, the practical difficulty of exploiting this path keeps the immediate risk moderate to high in potential impact but low in expected exploitation probability.

Generated by OpenCVE AI on September 19, 2026 at 13:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that includes the a6xx_gpu_init use‑after‑free fix.
  • If a kernel upgrade is not feasible, manually apply the commit or the patch available at https://patchwork.freedesktop.org/patch/732275/ to rebuild the affected driver.
  • For systems that do not require Adreno GPU functionality, unload or disable the drm/msm/adreno module to prevent the vulnerable initialization from occurring until a patch is applied.

Generated by OpenCVE AI on September 19, 2026 at 13:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Linux kernel
Weaknesses CWE-416
Vendors & Products Linux kernel

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/msm/adreno: fix use after free on error path in a6xx_gpu_init() The a6xx_destroy() function frees "a6xx_gpu" and so "adreno_gpu" points to freed memory. Preserve the error code before freeing the memory to avoid a use after free. Patchwork: https://patchwork.freedesktop.org/patch/732275/
Title drm/msm/adreno: fix use after free on error path in a6xx_gpu_init()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Kernel Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:47.123Z

Reserved: 2026-09-17T15:57:05.659Z

Link: CVE-2026-93060

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:59.660

Modified: 2026-09-17T17:17:59.660

Link: CVE-2026-93060

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T13:15:16Z

Weaknesses