CVE-2026-53347
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/07/2026
Last modified:
22/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
drm/virtio: Fix driver removal with disabled KMS<br />
<br />
DRM atomic and modesetting aren&#39;t initialized if virtio-gpu driver built<br />
with disabled KMS, leading to access of uninitialized data on driver<br />
removal/unbinding and crashing kernel. Fix it by skipping shutting down<br />
atomic core with unavailable KMS.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.4 (including) | 6.6.143 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.94 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.36 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 7.0.13 (excluding) |
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc7:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/15e561869a8b4e4db69733be1d6f33770664f989
- https://git.kernel.org/stable/c/19a6a00ff50c284f3a9818882ad2be58b33b790a
- https://git.kernel.org/stable/c/38a5f891cda6d121c149c94cda89c31ec7024ee3
- https://git.kernel.org/stable/c/ed3e134700a2e07caa99b9bc0683ebbe0327c562
- https://git.kernel.org/stable/c/f329e8325e054bd6d84d10904f8dd51137281b92



