Executive brief
A vulnerability in the Linux kernel's Atmel LCD controller driver could allow a local user to crash the system or potentially execute unauthorized code. The issue occurs when the system incorrectly manages memory while handling display updates, especially when multiple applications are trying to access the display hardware simultaneously. This could lead to system instability or a complete service outage.
Technical details
A use-after-free (UAF) vulnerability exists in the atmel-hlcdc DRM driver within the Linux kernel. The root cause is located in the atmel_hlcdc_plane_atomic_duplicate_state() callback, which manually copied the plane state structure without properly duplicating the underlying drm_plane_state. This resulted in the 'commit' pointer remaining tied to the old state, leading to a UAF during subsequent drm_atomic_commit() operations. The issue is triggerable locally, particularly when closing and re-opening device nodes while other DRM clients (like fbdev) are active. Patches have been released across multiple stable kernel branches to replace the manual copy with the standard __drm_atomic_helper_plane_duplicate_state() helper.
Affected products
- Linux Linux kernel 4.1 to 5.10.252, 5.11 to 5.15.202, 5.16 to 6.1.165, 6.2 to 6.6.128, 6.7 to 6.12.75, 6.13 to 6.18.16, 6.19 to 6.19.6
Timeline
- 2025-10-24: other: Patch authored
- 2026-05-06: disclosed: CVE published
- 2026-03-04: patched: Patches committed to stable trees
References
- https://git.kernel.org/stable/c/549c6db503dbb85dbff4840830971853feac6625
- https://git.kernel.org/stable/c/6404898af86d986db1dbbe06177c143e40652e49
- https://git.kernel.org/stable/c/796e77c14c4c1e2cd36473760fb6cc66c695eb47
- https://git.kernel.org/stable/c/7b4d0fab3ff2c00c6d34e1952c9df5129a826aee
- https://git.kernel.org/stable/c/a205740a7231e967ac77cb731171642901c327af
- https://git.kernel.org/stable/c/ac2d898da5095d46bd1ff8585fdd753d58ad91e7
- https://git.kernel.org/stable/c/bc847787233277a337788568e90a6ee1557595eb