CVE-2026-53058

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
24/06/2026
Last modified:
21/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> drm/bridge: cadence: cdns-mhdp8546-core: Set the mhdp connector earlier in atomic_enable()<br /> <br /> In case if we get errors in cdns_mhdp_link_up() or cdns_mhdp_reg_read()<br /> in atomic_enable, we will go to cdns_mhdp_modeset_retry_fn() and will hit<br /> NULL pointer while trying to access the mutex. We need the connector to<br /> be set before that. Unlike in legacy cases with flag<br /> !DRM_BRIDGE_ATTACH_NO_CONNECTOR, we do not have connector initialised<br /> in bridge_attach(), so add the mhdp-&gt;connector_ptr in device structure<br /> to handle both cases with DRM_BRIDGE_ATTACH_NO_CONNECTOR and<br /> !DRM_BRIDGE_ATTACH_NO_CONNECTOR, set it in atomic_enable() earlier to<br /> avoid possible NULL pointer dereference in recovery paths like<br /> modeset_retry_fn() with the DRM_BRIDGE_ATTACH_NO_CONNECTOR flag set.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.6 (including) 6.6.141 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.12.91 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.18.33 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (including) 7.0.10 (excluding)