Executive brief
A vulnerability was identified in the Linux kernel's MediaTek display driver. This component is responsible for managing graphics and display output on devices using MediaTek hardware. An exploit could allow a local attacker to cause a system crash or potentially execute unauthorized code, impacting the stability and security of the device.
Technical details
A use-after-free (UAF) vulnerability exists in the MediaTek DRM driver (mtk_drm_drv.c) within the mtk_drm_get_all_drm_priv function. The root cause is an incorrect reference count decrement of Open Firmware (OF) nodes during iteration. The for_each_child_of_node() helper automatically handles reference counting, but a redundant of_node_put() call was incorrectly added to every iteration of the loop. This leads to premature freeing of the node object while it is still being accessed. A local attacker could exploit this to cause a kernel panic (denial of service) or potentially execute arbitrary code in kernel context. Patches have been released for multiple stable kernel branches.
Affected products
- Linux Linux Kernel 6.6.105 to 6.6.107, 6.12.45 to 6.12.48, 6.16.5 to 6.16.8
Timeline
- 2025-09-23: disclosed: Initial publication of the vulnerability and fix.
- 2025-09-23: advisory