CVE-2026-98319
Received
Received - Intake
Memory Leak in Linux Kernel DRM Subsystem
Vulnerability report for CVE-2026-98319, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr
When an out_fence_ptr is provided but DRM_MODE_PAGE_FLIP_EVENT is not
set, a drm_pending_vblank_event will be allocated. If later, there is an
allocation failure or another failure at setup_out_fence(), that event
will not have base.fence set and it will not be released at
complete_signaling().
Release the event and set crtc_state->event to NULL just like in the
DRM_MODE_PAGE_FLIP_EVENT case when there is a failure at
drm_event_reserve_init(). That is, prepare_signaling() releases the
event and there is nothing to be done at complete_signaling(). Use
drm_event_cancel_free() as that will also undo drm_event_reserve_init()
in case it has been called.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | 92c715fca907686f5298220ece53423e38ba3aed |
| Linux | Linux | 92c715fca907686f5298220ece53423e38ba3aed |
| Linux | Linux | 92c715fca907686f5298220ece53423e38ba3aed |
| Linux | Linux | 92c715fca907686f5298220ece53423e38ba3aed |
| Linux | Linux | 92c715fca907686f5298220ece53423e38ba3aed |
| Linux | Linux | 92c715fca907686f5298220ece53423e38ba3aed |
| Linux | Linux | 92c715fca907686f5298220ece53423e38ba3aed |
| Linux | Linux | 92c715fca907686f5298220ece53423e38ba3aed |
| Linux | Linux | 4cd462c7f2b6fcc208aebf44f2c831681feaa925 |
| Linux | Linux | 4.9.10 |
| Linux | Linux | 4.10 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |