Description
In the Linux kernel, the following vulnerability has been resolved:

drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr

When an out_fence_ptr is provided but DRM_MODE_PAGE_FLIP_EVENT is not
set, a drm_pending_vblank_event will be allocated. If later, there is an
allocation failure or another failure at setup_out_fence(), that event
will not have base.fence set and it will not be released at
complete_signaling().

Release the event and set crtc_state->event to NULL just like in the
DRM_MODE_PAGE_FLIP_EVENT case when there is a failure at
drm_event_reserve_init(). That is, prepare_signaling() releases the
event and there is nothing to be done at complete_signaling(). Use
drm_event_cancel_free() as that will also undo drm_event_reserve_init()
in case it has been called.
Published: 2026-10-06
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Memory Leak (Resource Exhaustion)
Action: Patch Kernel
AI Analysis

Impact

In the Linux kernel’s Direct Rendering Manager, a memory leak occurs when an out_fence_ptr is supplied without the DRM_MODE_PAGE_FLIP_EVENT flag. The kernel allocates a drm_pending_vblank_event, but if a subsequent allocation or setup failure occurs, the event is not freed, causing persistent kernel memory exhaustion. This flaw is a resource‑management defect that can degrade system stability over time and may lead to a denial‑of‑service condition, but it does not provide direct remote code execution or privilege escalation.

Affected Systems

All Linux kernel builds before the resolution commit are affected wherever DRM devices are exposed. Systems running the kernel on hardware that supports DRM should assess whether they could trigger page‑flip operations that use out_fence_ptrs. No specific version numbers are enumerated, so any kernel version preceding the commit identified in the CVE’s background commits is considered vulnerable.

Risk and Exploitability

The CVSS score is not provided and the EPSS score is unavailable, indicating no publicly documented exploitation probability. The vulnerability is not listed in CISA KEV, so no known widespread exploitation is reported. The likely attack vector is local exploitation by a user or application with DRM access; triggering page‑flip events that fail with an out_fence_ptr can exhaust kernel memory. The impact remains limited to memory resource exhaustion and potential service interruption, but requires sufficient privilege to invoke DRM operations.

Generated by OpenCVE AI on October 6, 2026 at 14:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to the most recent version that includes the commit fixing the drm_pending_vblank_event leak; this patch releases the event and clears crtc_state.
  • After the kernel update, restart the display server (Xorg, Wayland, etc.) or reboot to load the updated DRM code.
  • Configure applications to use page‑flip events only with valid fence pointers and the DRM_MODE_PAGE_FLIP_EVENT flag, or disable page‑flip events if they are unnecessary, to prevent the error path that triggers the memory leak.

Generated by OpenCVE AI on October 6, 2026 at 14:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401
CWE-459

Tue, 06 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr When an out_fence_ptr is provided but DRM_MODE_PAGE_FLIP_EVENT is not set, a drm_pending_vblank_event will be allocated. If later, there is an allocation failure or another failure at setup_out_fence(), that event will not have base.fence set and it will not be released at complete_signaling(). Release the event and set crtc_state->event to NULL just like in the DRM_MODE_PAGE_FLIP_EVENT case when there is a failure at drm_event_reserve_init(). That is, prepare_signaling() releases the event and there is nothing to be done at complete_signaling(). Use drm_event_cancel_free() as that will also undo drm_event_reserve_init() in case it has been called.
Title drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-06T08:46:13.948Z

Reserved: 2026-09-25T10:25:14.340Z

Link: CVE-2026-98319

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T09:18:23.800

Modified: 2026-10-06T09:18:23.800

Link: CVE-2026-98319

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T14:30:07Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime

  • CWE-459

    Incomplete Cleanup