Executive brief
The AMD display driver in the Linux kernel contains a memory management bug in the CRTC (cathode ray tube controller) reset function used for graphics output configuration. If memory allocation fails during a reset operation, the function leaves a pointer to freed memory in place, which could lead to crashes or unpredictable system behavior when the graphics subsystem attempts subsequent operations.
Technical details
The vulnerability is a use-after-free condition in the amdgpu_dm_crtc_reset_state() function within drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_crtc.c. The function originally freed the old CRTC state before allocating a new one; if the kzalloc() call failed, the state pointer would dangle, referencing already-freed memory. The fix reorders the operations to attempt allocation of the new state first, and only destroys the old state on successful allocation. On allocation failure, the old state remains valid and the function safely returns. This is a memory safety issue requiring no user interaction or elevated privileges, affecting only the graphics subsystem.
Affected products
- Linux Linux kernel Affected versions include linux-5.x, linux-6.x, and linux-7.x (patched via commit 0aeed866cb938943908c3ba46422128e49d2d080 and backports)
Timeline
- 2026-09-17: disclosed: CVE-2026-93175 published
- 2026-06-29: patched: Fix committed upstream by Evgenii Burenchev
- 2026-07-01: patched: Fix merged by Alex Deucher