Description
In the Linux kernel, the following vulnerability has been resolved:

drm/bridge: synopsys: dw-dp: Support unregistering the AUX channel

The DisplayPort AUX channel gets initialized and registered during
dw_dp_bind(), but it is never unregistered, which may lead to resource
leaks and/or use-after-free.

Add the missing dw_dp_unbind() function to allow the users of the
library to handle the required cleanup, i.e. unregister the AUX adapter.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use-After-Free / Privilege Escalation
Action: Patch ASAP
AI Analysis

Impact

During binding the DisplayPort AUX channel is initialized and registered, but the corresponding unbind routine was omitted. The missing cleanup can lead to resource leaks and, more critically, a use‑after‑free in the kernel. An attacker who can cause the driver to reference freed memory may execute arbitrary code with kernel privileges. The weakness is characteristic of improper resource management and use‑after‑free vulnerabilities (CWE‑416, CWE‑401).

Affected Systems

The flaw is present in the Linux kernel, affecting all distributions that ship the unpatched kernel code. No specific version range is listed, so any kernel containing the obsolete dw_dp_bind implementation without a matching dw_dp_unbind is potentially vulnerable. This includes standard production kernels as well as custom builds that use the Synopsys DisplayPort driver.

Risk and Exploitability

The EPSS score is below 1 % and the issue has not been catalogued by CISA as a known exploited vulnerability, indicating a low current exploitation probability. Nonetheless, the high severity of a kernel use‑after‑free, combined with local or privileged code execution potential, gives the vulnerability a high severity rating. Attackers would need to gain local access to send crafted requests to the DisplayPort subsystem or to trigger a path that forces the use of a dangling AUX channel reference. The vulnerability is likely exploitable only within the local machine context but can result in full system compromise.

Generated by OpenCVE AI on September 19, 2026 at 08:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a kernel version that includes the dw_dp_unbind implementation or apply the patch from the kernel Git repository indicated in the advisories. The patch registers a proper unbind routine that cleans up the AUX channel during driver removal.
  • If a full kernel upgrade is not immediately possible, manually cherry‑pick the dw_dp_unbind commit (or a backport) from the upstream repository and apply it to the running kernel source. Rebuild and reload the affected driver module to force the cleanup logic to execute.
  • After applying the fix, reboot the system or unload/reload the display driver to ensure the AUX channel is fully unregistered and no dangling references remain. Monitor kernel logs for any residual warning or error messages related to the DisplayPort driver that could indicate incomplete cleanup.

Generated by OpenCVE AI on September 19, 2026 at 08:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/bridge: synopsys: dw-dp: Support unregistering the AUX channel The DisplayPort AUX channel gets initialized and registered during dw_dp_bind(), but it is never unregistered, which may lead to resource leaks and/or use-after-free. Add the missing dw_dp_unbind() function to allow the users of the library to handle the required cleanup, i.e. unregister the AUX adapter.
Title drm/bridge: synopsys: dw-dp: Support unregistering the AUX channel
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:12:18.457Z

Reserved: 2026-09-17T16:02:15.092Z

Link: CVE-2026-93195

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:15.777

Modified: 2026-09-17T17:18:15.777

Link: CVE-2026-93195

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:30:17Z

Weaknesses

No weakness.