Description
In the Linux kernel, the following vulnerability has been resolved:

drm/amd/display: Fix dangling pointer in plane reset function

amdgpu_dm_plane_drm_plane_reset() frees the old state before allocating
a new one. If kzalloc() fails, the function returns without updating
the state pointer, leaving a dangling pointer to already freed memory.

Fix this by allocating the new state first. On allocation failure, the
old state remains untouched and the function safely returns.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

[adjust for movement around current amd-staging-drm-next]
Published: 2026-09-17
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Use-After-Free
Action: Apply Patch
AI Analysis

Impact

The vulnerability lies in the amdgpu_dm_plane_drm_plane_reset() function within the Linux kernel's AMDGPU display driver. When allocation of a new plane state fails, the function exits without updating the state pointer, leaving it dangling to freed memory. This use‑after‑free could subsequently be dereferenced, corrupting kernel memory and potentially enabling arbitrary code execution by a privileged attacker.

Affected Systems

All Linux kernel builds that contain the amdgpu_dm module before the fix are affected. The issue is specific to the AMDGPU driver and does not impact other graphics drivers. Inferred: the affected hardware is likely AMD GPUs, but this is not explicitly stated.

Risk and Exploitability

The CVSS score of 7 indicates a severe impact if exploited. The EPSS score of <1% and the lack of a CISA KEV listing suggest a low probability of active exploitation. The use‑after‑free in kernel space could enable arbitrary code execution; however, the specific attack surface or vector is not detailed in the supplied information, and it is inferred that an attacker with local kernel privileges would be required to exploit it.

Generated by OpenCVE AI on September 19, 2026 at 15:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the fix for this vulnerability.
  • If using a custom or older kernel, apply the patch from the referenced commits (see the kernel git URLs).
  • Reboot the system after applying the update to ensure the new kernel and driver are active.

Generated by OpenCVE AI on September 19, 2026 at 15:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix dangling pointer in plane reset function amdgpu_dm_plane_drm_plane_reset() frees the old state before allocating a new one. If kzalloc() fails, the function returns without updating the state pointer, leaving a dangling pointer to already freed memory. Fix this by allocating the new state first. On allocation failure, the old state remains untouched and the function safely returns. Found by Linux Verification Center (linuxtesting.org) with SVACE. [adjust for movement around current amd-staging-drm-next]
Title drm/amd/display: Fix dangling pointer in plane reset function
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:56:22.149Z

Reserved: 2026-09-17T16:02:15.090Z

Link: CVE-2026-93176

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:13.397

Modified: 2026-09-18T18:18:23.660

Link: CVE-2026-93176

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T18:30:16Z

Weaknesses