CVE-2026-90363
Last modified
CVE-2026-90363 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: drm/msm: don't tear down KMS twice when KMS init fails When priv->kms_init() (mdp4_kms_init() / mdp5_kms_init()) fails partway through, both display drivers already tear their KMS state down via mdp4_destroy() / mdp5_kms_destroy() before returning the error. The common error path in msm_drm_init() then runs msm_drm_uninit() -> msm_drm_kms_uninit(), which tries to destroy the very same KMS a second time, which causes a use-after-free crash. Bring MDP4/MDP5 in line with the DPU driver whose dpu_kms_init() doesn't perform error cleanup on the failure.
Description
In the Linux kernel, the following vulnerability has been resolved: drm/msm: don't tear down KMS twice when KMS init fails When priv->kms_init() (mdp4_kms_init() / mdp5_kms_init()) fails partway through, both display drivers already tear their KMS state down via mdp4_destroy() / mdp5_kms_destroy() before returning the error. The common error path in msm_drm_init() then runs msm_drm_uninit() -> msm_drm_kms_uninit(), which tries to destroy the very same KMS a second time, which causes a use-after-free crash. Bring MDP4/MDP5 in line with the DPU driver whose dpu_kms_init() doesn't perform error cleanup on the failure. Let the common path own the cleanup, instead of freeing the KMS from their error paths. The crash trace for the reference: __lock_acquire from lock_acquire (kernel/locking/lockdep.c:5906 kernel/locking/lockdep.c:5863) lock_acquire from touch_wq_lockdep_map (kernel/workqueue.c:4094 (discriminator 1)) touch_wq_lockdep_map from __flush_workqueue (kernel/workqueue.c:4136) __flush_workqueue from msm_drm_kms_uninit (drivers/gpu/drm/msm/msm_kms.c:243 (discriminator 33)) msm_drm_kms_uninit from msm_drm_uninit (drivers/gpu/drm/msm/msm_drv.c:93) msm_drm_uninit from msm_drm_init (drivers/gpu/drm/msm/msm_drv.c:184) msm_drm_init from try_to_bring_up_aggregate_device (drivers/base/component.c:249 drivers/base/component.c:227) try_to_bring_up_aggregate_device from __component_add (drivers/base/component.c:269 drivers/base/component.c:748) __component_add from dsi_host_attach (drivers/gpu/drm/msm/dsi/dsi_host.c:1739) dsi_host_attach from mipi_dsi_attach (drivers/gpu/drm/drm_mipi_dsi.c:383) mipi_dsi_attach from sharp_nt_panel_probe (drivers/gpu/drm/panel/panel-sharp-ls043t1le01.c:247) Patchwork: https://patchwork.freedesktop.org/patch/742068/
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 506efcba31296e9cbc4f8f148eec1e4b29039931, < 08827aa40f0ee9d37dcff8d6acb340b970051486; >= 506efcba31296e9cbc4f8f148eec1e4b29039931, < e2a99fa93b400dfbb9598103249f71969501094a; >= 506efcba31296e9cbc4f8f148eec1e4b29039931, < 93c125e4ea98fb25f927ba5a334d85845127d667 |
| Linux | Linux | 6.7 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-90363?
How severe is CVE-2026-90363?
How do I fix CVE-2026-90363?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-90358In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-90359In the Linux kernel, the following vulnerability has been re…
- CVE-2026-9036IBM Netezza Software 11.3.0.3 through Interim Fix 002 does n…5.9
- CVE-2026-90360In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90361In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90362In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90364In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90365In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90366In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90367In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-90368In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90369In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-90363?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
