Executive brief
A vulnerability in the Linux kernel's HiSilicon Hibmc display driver can cause a system crash. When the driver fails to load properly, it attempts to clean up resources that were never initialized, leading to a null pointer dereference. This issue primarily impacts system availability, potentially allowing a local user to cause a denial-of-service (system crash).
Technical details
A NULL pointer dereference exists in the hibmc_load() function within drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_drv.c. When hibmc_hw_init() or drmm_vram_helper_init() fails, the driver executes a 'goto err' statement which calls hibmc_unload(). However, hibmc_unload() attempts to access mutexes in mode.config that have not yet been initialized, resulting in a kernel panic. The fix replaces the 'goto' statements with direct returns to avoid the premature cleanup of uninitialized structures. This is a local vulnerability (CWE-476) that can be triggered by a user with sufficient privileges to load or interact with the driver, resulting in a Denial of Service (DoS).
Affected products
- Linux Linux Kernel 4.14 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.44, 6.13 to 6.16.4
Timeline
- 2025-08-13: patched: Initial patch authored by Baihan Li
- 2025-09-11: disclosed: CVE published by kernel.org
- 2025-10-01: advisory: Debian LTS advisory published
References
- https://git.kernel.org/stable/c/93a08f856fcc5aaeeecad01f71bef3088588216a
- https://git.kernel.org/stable/c/a4f1b9c57092c48bdc7958abd23403ccaed437b2
- https://git.kernel.org/stable/c/c950e1be3a24d021475b56efdb49daa7fbba63a9
- https://git.kernel.org/stable/c/d3e774266c28aefab3e9db334fdf568f936cae04
- https://git.kernel.org/stable/c/ddf1691f25345699296e642f0f59f2d464722fa3
- https://git.kernel.org/stable/c/f93032e5d68f459601c701f6ab087b5feb3382e8
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html