Junglewise Threat Intelligence

CVE-2026-93194: Linux kernel drm/rockchip dw_dp resource leak

CVE-2026-93194 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Rockchip display driver fails to properly release DisplayPort AUX channel resources during shutdown or error conditions. This can cause memory leaks and use-after-free errors, potentially leading to system instability or crashes on Rockchip-based embedded systems.

Technical details

A resource cleanup vulnerability in the drm/rockchip dw_dp (Designware DisplayPort) driver where core resources, including the DisplayPort AUX channel, are initialized and registered in dw_dp_bind() but never unregistered. This omission can lead to memory leaks and use-after-free conditions, as evidenced by KASAN reports showing use-after-free in device_is_dependent(). The fix involves calling the previously exported dw_dp_unbind() function in both the component's unbind() callback and its bind() error path to ensure proper cleanup.

Affected products

  • Linux Linux kernel 7.0.0-rc2 and earlier (drm/rockchip component)

Timeline

  • 2026-09-17: disclosed

Related threats