Impact
In the Linux kernel’s Direct Rendering Manager, a memory leak occurs when an out_fence_ptr is supplied without the DRM_MODE_PAGE_FLIP_EVENT flag. The kernel allocates a drm_pending_vblank_event, but if a subsequent allocation or setup failure occurs, the event is not freed, causing persistent kernel memory exhaustion. This flaw is a resource‑management defect that can degrade system stability over time and may lead to a denial‑of‑service condition, but it does not provide direct remote code execution or privilege escalation.
Affected Systems
All Linux kernel builds before the resolution commit are affected wherever DRM devices are exposed. Systems running the kernel on hardware that supports DRM should assess whether they could trigger page‑flip operations that use out_fence_ptrs. No specific version numbers are enumerated, so any kernel version preceding the commit identified in the CVE’s background commits is considered vulnerable.
Risk and Exploitability
The CVSS score is not provided and the EPSS score is unavailable, indicating no publicly documented exploitation probability. The vulnerability is not listed in CISA KEV, so no known widespread exploitation is reported. The likely attack vector is local exploitation by a user or application with DRM access; triggering page‑flip events that fail with an out_fence_ptr can exhaust kernel memory. The impact remains limited to memory resource exhaustion and potential service interruption, but requires sufficient privilege to invoke DRM operations.
OpenCVE Enrichment