Junglewise Threat Intelligence

CVE-2026-93195: Linux kernel DisplayPort AUX channel resource leak in dw-dp bridge

CVE-2026-93195 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's DisplayPort bridge driver (dw-dp) fails to properly clean up the AUX (auxiliary) channel used for communication between graphics and display devices. This resource leak can cause memory to be wasted and potentially lead to system instability when the driver is unloaded or reloaded multiple times.

Technical details

The vulnerability is a resource leak in the Synopsys DesignWare DisplayPort bridge driver (drivers/gpu/drm/bridge/synopsys/dw-dp.c). During initialization, the dw_dp_bind() function registers a DisplayPort AUX adapter channel, but the corresponding cleanup function dw_dp_unbind() was missing, preventing proper unregistration and deallocation. This can lead to use-after-free conditions and memory leaks when the driver module is unloaded. The fix adds the missing dw_dp_unbind() function that calls drm_dp_aux_unregister() to properly clean up the AUX channel. No authentication or user interaction is required to trigger the leak—it occurs automatically when affected kernel versions are used without the patch.

Affected products

  • Linux Linux kernel Linux 5.x-6.x versions before the fix (Upstream commit ed04e8e2307f35b3d8d49a554faf5e72d3d224e6)

Timeline

  • 2026-09-17: disclosed: Published on NVD and Linux stable repositories
  • 2026-06-01: patched: Fix committed upstream by Cristian Ciocaltea

References

Related threats