Junglewise Threat Intelligence

CVE-2026-53279: Linux Kernel system hang in drm/gma500 oaktrail_lvds initialization

CVE-2026-53279 · Severity: info · CVSS 0 · Published 2026-06-26

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's graphics driver for certain Intel-based mobile devices. If the system fails to initialize the display hardware correctly, it can enter an indefinite hang state, leading to a complete system freeze or denial of service. This issue primarily affects the reliability and availability of devices using the affected hardware.

Technical details

A resource management flaw exists in the drm/gma500/oaktrail_lvds driver within the Linux kernel. The LVDS initialization sequence attempts to acquire an I2C adapter via i2c_get_adapter(); if a subsequent initialization step fails, the error handling path incorrectly attempts to deregister and free the adapter even if it was a pre-existing system adapter rather than one newly allocated by the driver. Because i2c_get_adapter() increments the reference count, the deregistration process waits indefinitely for the reference to be released, resulting in a kernel hang. The fix ensures that only driver-allocated adapters are destroyed during error cleanup.

Affected products

  • Linux Linux 6.0 to 7.1

Timeline

  • 2026-05-08: other: Patch authored
  • 2026-06-26: advisory: CVE published

References