Junglewise Threat Intelligence

CVE-2026-64154: Linux kernel Adreno GPU reference leak in a6xx_gpu_init

CVE-2026-64154 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's graphics driver for Adreno GPUs. This issue involves a memory management error where certain system resources are not properly released during initialization failures. While primarily a technical stability issue, such leaks can theoretically lead to system instability or resource exhaustion over time.

Technical details

A reference leak exists in the a6xx_gpu_init() function within drivers/gpu/drm/msm/adreno/a6xx_gpu.c. The function obtains a device node reference via of_parse_phandle() but fails to release it using of_node_put() when encountering early error return paths. This is a classic resource management bug where the reference count for a device tree node is incremented but never decremented if the initialization fails prematurely. The fix implements the __free(device_node) cleanup handler to ensure the reference is automatically released when the variable goes out of scope. This issue affects Linux kernel versions from 6.5 up to 7.0.11.

Affected products

  • Linux Linux kernel 6.5 to 7.0.11

Timeline

  • 2026-07-19: disclosed
  • 2026-07-19: advisory

References

Related threats