CVE-2026-68236

Source
https://cve.org/CVERecord?id=CVE-2026-68236
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68236.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-68236
Downstream
BELL (1)
DEBIAN (1)
MGASA (2)
openSUSE (1)
SUSE (10)
UBUNTU (1)
Related
Published
2026-08-10T12:01:01Z
Modified
2026-10-05T02:30:26Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
drm/amd/display: set new_stream to NULL after release
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/amd/display: set new_stream to NULL after release

In dm_update_crtc_state(), the skip_modeset path releases new_stream via dc_stream_release() but does not set the pointer to NULL.

If a later error (e.g., color management failure) triggers the fail label, the error path calls dc_stream_release() again on the same dangling pointer, causing a double release and potential use-after-free.

Fix this by setting new_stream to NULL after the initial release.

(cherry picked from commit 99f3af19073b3ddbfd96e789124cce12c4277b28)

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68236.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9b690ef3c70422cdcd0cf912db33f2c92ef4a53f
Fixed
92b7c6e3a1546c6db868b07e93fa6fb950d1d3a0
Fixed
bf9c06c70f496f1ba4474caf95c69696c828340e
Fixed
01ba5b36898d6258f584269537cc49e7b05cf7c6
Fixed
ba8bf1dcbb44773e7a0fd13b42925c644e0d5e76
Fixed
5182e442e61397d446c36995b8f5676942d35b82
Fixed
679f23f0a3606afcef1ffabd72222f00a54ad9e3
Fixed
0676fecbb5242aa22c057e78326d6d6041db034c
Fixed
9fa26b9eed6195bf840f39ac183b9a6237548755

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68236.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.15.0
Fixed
5.10.271
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.222
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68236.json"