CVE-2026-53058
Severity CVSS v4.0:
Pending analysis
Type:
CWE-476
NULL Pointer Dereference
Publication date:
24/06/2026
Last modified:
21/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
drm/bridge: cadence: cdns-mhdp8546-core: Set the mhdp connector earlier in atomic_enable()<br />
<br />
In case if we get errors in cdns_mhdp_link_up() or cdns_mhdp_reg_read()<br />
in atomic_enable, we will go to cdns_mhdp_modeset_retry_fn() and will hit<br />
NULL pointer while trying to access the mutex. We need the connector to<br />
be set before that. Unlike in legacy cases with flag<br />
!DRM_BRIDGE_ATTACH_NO_CONNECTOR, we do not have connector initialised<br />
in bridge_attach(), so add the mhdp->connector_ptr in device structure<br />
to handle both cases with DRM_BRIDGE_ATTACH_NO_CONNECTOR and<br />
!DRM_BRIDGE_ATTACH_NO_CONNECTOR, set it in atomic_enable() earlier to<br />
avoid possible NULL pointer dereference in recovery paths like<br />
modeset_retry_fn() with the DRM_BRIDGE_ATTACH_NO_CONNECTOR flag set.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.6 (including) | 6.6.141 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.91 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.33 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 7.0.10 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/1af3b42e08a957e53bab8e1897393fe0a27d9fbf
- https://git.kernel.org/stable/c/43d6508ddbf9fb974fbc359a033154f78c9d4c8b
- https://git.kernel.org/stable/c/5302015daf26ef6b48e067f2b86c9482ac19e015
- https://git.kernel.org/stable/c/a3611554e599d1a24b45fd8415bacb72ce861e4b
- https://git.kernel.org/stable/c/cf2ac2cac8b319f89b3a3851ca0c5ffb6a549575



