Description
In the Linux kernel, the following vulnerability has been resolved:

drm/rockchip: analogix_dp: Fix OF node reference leak via auto cleanup

Sashiko reported a reference leak in rockchip_dp_drm_encoder_enable(),
the of_get_child_by_name() function does not call of_node_put() in a
symmetrical way [1].

Fix the device node reference leak by using __free(device_node) to
automatically manage of_node_put() for all device nodes.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Device Node Reference Leak
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a reference leak in the rockchip driver’s DP encoder enable function where the of_node reference is not properly released. This leads to an uncontrolled accumulation of device node references, potentially exhausting kernel memory or refcounted objects and causing instability or denial of service. The weakness falls under resource management failures.

Affected Systems

The issue is present in the Linux kernel, specifically the rockchip DRM driver module. No particular kernel versions are listed, so all affected kernel releases that contain the driver before the commit 396a193867c6 are potentially impacted. The vendor identified is the Linux kernel itself.

Risk and Exploitability

The EPSS score of less than 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The bug is limited to the local environment where the driver is loaded, typically on devices with Rockchip SoCs; it does not expose a network access vector. Due to the non‑persistent nature of leaked references, an attacker would need physical or local system access and would likely trigger a denial of service through resource exhaustion rather than remote code execution.

Generated by OpenCVE AI on September 19, 2026 at 08:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the commit fixing the reference leak
  • Reboot the system to load the updated kernel
  • If an immediate kernel upgrade is not possible, disable the Rockchip DRM driver by blacklisting or removing its configuration to prevent the bug from being triggered

Generated by OpenCVE AI on September 19, 2026 at 08:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-399

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/rockchip: analogix_dp: Fix OF node reference leak via auto cleanup Sashiko reported a reference leak in rockchip_dp_drm_encoder_enable(), the of_get_child_by_name() function does not call of_node_put() in a symmetrical way [1]. Fix the device node reference leak by using __free(device_node) to automatically manage of_node_put() for all device nodes.
Title drm/rockchip: analogix_dp: Fix OF node reference leak via auto cleanup
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:12:17.117Z

Reserved: 2026-09-17T16:02:15.092Z

Link: CVE-2026-93193

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:15.553

Modified: 2026-09-17T17:18:15.553

Link: CVE-2026-93193

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T21:00:08Z

Weaknesses