Executive brief
The Linux kernel's OMAP display subsystem (used in graphics/display drivers for certain ARM SoCs) had a use-after-free vulnerability in its interrupt service routine handling. The flaw could allow a local attacker to trigger a kernel crash or potentially execute code by unregistering interrupts while they are being serviced, leading to access of freed memory objects on the stack.
Technical details
The vulnerability is a use-after-free (UAF) in the DRM OMAP DSI (Display Serial Interface) driver's interrupt handler. The root cause is improper lifetime management of stack-allocated objects passed to interrupt service routines. The code previously copied the interrupt service routine (ISR) table to allow ISRs to unregister themselves, but this pattern enabled a race condition: if IRQs were unregistered while being handled, the handler would access freed stack-allocated objects. The fix removes the unnecessary table copy and calls the ISR handler directly on the original table. This is a local vector requiring no authentication; exploitability depends on kernel configuration and system access privileges.
Affected products
- Linux Linux kernel multiple versions in 4.x, 5.x, 6.x, 7.x series (drm/omap DSI subsystem)
Timeline
- 2026-09-17: disclosed
- 2026-07-02: patched: Upstream fix authored by Andreas Kemnade
- 2026-09-14: other: Committed to stable kernel tree by Greg Kroah-Hartman