Home

Description

In the Linux kernel, the following vulnerability has been resolved: drm/gud: fix NULL fb and crtc dereferences on USB disconnect On disconnect drm_atomic_helper_disable_all() is called which sets both the fb and crtc for a plane to NULL before invoking a commit. This causes a kernel oops on every display disconnect. Add guards for those dereferences.

PUBLISHED Reserved 2026-01-13 | Published 2026-01-31 | Updated 2026-01-31 | Assigner Linux

Product status

Default status
unaffected

73cfd166e045769a1b42d36897accaa6e06b8102 (git) before a255ec07f91d4c73a361a28b7a3d82f5710245f1
affected

73cfd166e045769a1b42d36897accaa6e06b8102 (git) before dc2d5ddb193e363187bae2ad358245642d2721fb
affected

Default status
affected

6.18
affected

Any version before 6.18
unaffected

6.18.7 (semver)
unaffected

6.19-rc6 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/a255ec07f91d4c73a361a28b7a3d82f5710245f1

git.kernel.org/...c/dc2d5ddb193e363187bae2ad358245642d2721fb

cve.org (CVE-2026-23039)

nvd.nist.gov (CVE-2026-23039)

Download JSON