In the Linux kernel, the following vulnerability has been resolved:
drm/i915: Grab intel_display from the encoder to avoid potential oopsies
Grab the inteldisplay from 'encoder' rather than 'state' in the encoder hooks to avoid the massive footgun that is intelsanitizeencoder(), which passes NULL as the 'state' argument to encoder .disable() and .postdisable().
TODO: figure out how to actually fix intelsanitizeencoder()...