CVE-2026-52966

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/06/2026
Last modified:
14/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> drm: Replace old pointer to new idr<br /> <br /> Commit 5e28b7b94408 introduced a logical error by failing to replace the<br /> newly generated IDR pointer to old id&amp;#39;s pointer at the correct location<br /> within the "change handle" logic; this resulted in the issue reported by<br /> syzbot [1].<br /> <br /> Specifically, the new IDR object pointer is intended to replace the original<br /> id&amp;#39;s pointer during the normal execution flow.<br /> <br /> Additionally, an unnecessary conditional check for the ret exit path has<br /> been removed.<br /> <br /> [1]<br /> !RB_EMPTY_ROOT(&amp;prime_fpriv-&gt;dmabufs)<br /> WARNING: drivers/gpu/drm/drm_prime.c:224 at drm_prime_destroy_file_private+0x48/0x60 drivers/gpu/drm/drm_prime.c:224, CPU#0: syz.0.17/5833<br /> Call Trace:<br /> drm_file_free.part.0+0x7e6/0xcc0 drivers/gpu/drm/drm_file.c:269<br /> drm_file_free drivers/gpu/drm/drm_file.c:237 [inline]<br /> drm_close_helper.isra.0+0x186/0x200 drivers/gpu/drm/drm_file.c:290<br /> drm_release+0x1ab/0x360 drivers/gpu/drm/drm_file.c:438

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:6.18.32:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0.9:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*