Executive brief
A vulnerability was identified in the Linux kernel's display driver for Qualcomm chipsets. It occurs when the system attempts to shut down the driver while a user application still holds a reference to the display hardware, potentially leading to a system crash. This could allow a local user to cause a denial-of-service by triggering a kernel instability.
Technical details
A use-after-free vulnerability exists in the dpu_writeback_init() function within the Linux kernel's MSM DRM driver (drivers/gpu/drm/msm/disp/dpu1/dpu_writeback.c). The root cause is the mixing of devm and drmm memory management functions; specifically, WB connector data allocated with devm_kzalloc() is freed during driver teardown even if userspace still holds a reference to the DRM device. If userspace subsequently attempts to interact with the connector, it accesses freed memory. This can be triggered by a local user during driver teardown. The issue has been resolved by migrating the allocation to drmm_kzalloc() to ensure the memory lifetime matches the DRM device's lifetime.
Affected products
- Linux Linux 6.18, 7.0, 7.1
Timeline
- 2026-05-05: other: Initial patch authored
- 2026-07-19: advisory: CVE published