CVE-2026-90297
Published: September 19, 2026Last modified: September 19, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: drm/sun4i: crtc: Propagate layer initialization error sun4i_crtc_init() returns plain NULL when layer initialization fails, while all its other error paths return an error pointer. The only caller, sun4i_tcon_bind(), checks the result with IS_ERR() and happily continues with tcon->crtc set to NULL. sun4i_rgb_init() and sun4i_lvds_init() then dereference it in drm_crtc_mask(), which oopses. Return the error pointer instead.
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 23 LTS | linux-lts | Vulnerable (6.1.182-r0) |
| 25 LTS | linux-lts | Vulnerable (6.12.103-r0) | |
| Stream | linux-lts | Vulnerable (6.18.46-r0) |
References
- https://git.kernel.org/stable/c/1882112124a642de7571fbf354fa1929decbb3ef
- https://git.kernel.org/stable/c/2bb3169788f8296c8fc1e0d4fa6f1c6367cd5829
- https://git.kernel.org/stable/c/65bc02fec98e4e1d7d59d86cf2ddf8fd73dacb89
- https://git.kernel.org/stable/c/7061ff05ed4a3cf16e83f7e3ad09cbd212508a32
- https://git.kernel.org/stable/c/8f32af44d43332c02198752e596df00659bf4354
- https://git.kernel.org/stable/c/aaf812960fb5ade24be7a1d8fea27a1ffc458c30
- https://git.kernel.org/stable/c/c0d3219ffd4c0d42295e0dc949856067b7818b71
- https://git.kernel.org/stable/c/e216d6168f25a69e5ae5b981ee73b3a860a46441