CVE-2026-90297

Unknown

Last modified

CVE-2026-90297 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: drm/sun4i: crtc: Propagate layer initialization error sun4i_crtc_init() returns plain NULL when layer initialization fails, while all its other error paths return an error pointer. The only caller, sun4i_tcon_bind(), checks the result with IS_ERR() and happily continues with tcon->crtc set to NULL.

Description

In the Linux kernel, the following vulnerability has been resolved: drm/sun4i: crtc: Propagate layer initialization error sun4i_crtc_init() returns plain NULL when layer initialization fails, while all its other error paths return an error pointer. The only caller, sun4i_tcon_bind(), checks the result with IS_ERR() and happily continues with tcon->crtc set to NULL. sun4i_rgb_init() and sun4i_lvds_init() then dereference it in drm_crtc_mask(), which oopses. Return the error pointer instead.

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= dcd215801b0279f0a021516526cf7c0b67d5302e, < aaf812960fb5ade24be7a1d8fea27a1ffc458c30; >= dcd215801b0279f0a021516526cf7c0b67d5302e, < e216d6168f25a69e5ae5b981ee73b3a860a46441; >= dcd215801b0279f0a021516526cf7c0b67d5302e, < 2bb3169788f8296c8fc1e0d4fa6f1c6367cd5829; >= dcd215801b0279f0a021516526cf7c0b67d5302e, < 1882112124a642de7571fbf354fa1929decbb3ef; >= dcd215801b0279f0a021516526cf7c0b67d5302e, < 8f32af44d43332c02198752e596df00659bf4354; >= dcd215801b0279f0a021516526cf7c0b67d5302e, < 65bc02fec98e4e1d7d59d86cf2ddf8fd73dacb89; >= dcd215801b0279f0a021516526cf7c0b67d5302e, < c0d3219ffd4c0d42295e0dc949856067b7818b71; >= dcd215801b0279f0a021516526cf7c0b67d5302e, < 7061ff05ed4a3cf16e83f7e3ad09cbd212508a32
LinuxLinux4.12

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-90297?
In the Linux kernel, the following vulnerability has been resolved: drm/sun4i: crtc: Propagate layer initialization error sun4i_crtc_init() returns plain NULL when layer initialization fails, while all its other error paths return an error pointer. The only caller, sun4i_tcon_bind(), checks the result with IS_ERR() and happily continues with tcon->crtc set to NULL. sun4i_rgb_init() and sun4i_lvds_init() then dereference it in drm_crtc_mask(), which oopses. Return the error pointer instead.
How severe is CVE-2026-90297?
Severity scoring for CVE-2026-90297 is pending analysis.
How do I fix CVE-2026-90297?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-90297?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST