CVE-2026-98319
drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr
Description
In the Linux kernel, the following vulnerability has been resolved: drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr When an out_fence_ptr is provided but DRM_MODE_PAGE_FLIP_EVENT is not set, a drm_pending_vblank_event will be allocated. If later, there is an allocation failure or another failure at setup_out_fence(), that event will not have base.fence set and it will not be released at complete_signaling(). Release the event and set crtc_state->event to NULL just like in the DRM_MODE_PAGE_FLIP_EVENT case when there is a failure at drm_event_reserve_init(). That is, prepare_signaling() releases the event and there is nothing to be done at complete_signaling(). Use drm_event_cancel_free() as that will also undo drm_event_reserve_init() in case it has been called.
INFO
Published Date :
Oct. 6, 2026, 9:18 a.m.
Last Modified :
Oct. 6, 2026, 9:18 a.m.
Remotely Exploit :
No
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Solution
- Apply the kernel patch for DRM.
- Ensure event resources are released on failure.
- Set crtc_state->event to NULL on error.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-98319.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-98319 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-98319
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-98319 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-98319 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Oct. 06, 2026
Action Type Old Value New Value Added Description In the Linux kernel, the following vulnerability has been resolved: drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr When an out_fence_ptr is provided but DRM_MODE_PAGE_FLIP_EVENT is not set, a drm_pending_vblank_event will be allocated. If later, there is an allocation failure or another failure at setup_out_fence(), that event will not have base.fence set and it will not be released at complete_signaling(). Release the event and set crtc_state->event to NULL just like in the DRM_MODE_PAGE_FLIP_EVENT case when there is a failure at drm_event_reserve_init(). That is, prepare_signaling() releases the event and there is nothing to be done at complete_signaling(). Use drm_event_cancel_free() as that will also undo drm_event_reserve_init() in case it has been called. Added Affected New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/98xxx/CVE-2026-98319.json">CVE-2026-98319</a> Added Reference https://git.kernel.org/stable/c/3d6576ed3de01e8a378397b7020e33ae3d40aa6c Added Reference https://git.kernel.org/stable/c/780716e2e019186fa6e5aad097a44b87b0b5388f Added Reference https://git.kernel.org/stable/c/86c33f740aa27e9cdc1259f0cc59c9c58f545e4b Added Reference https://git.kernel.org/stable/c/88c450e23b8fd4f1dcd329562f5e81ef05f3d941 Added Reference https://git.kernel.org/stable/c/9eb1a393c89a79c4210230d23e7d88d239c61d7b Added Reference https://git.kernel.org/stable/c/b9a68a9ccaada15d8dd0102c188cc6b868ff800b Added Reference https://git.kernel.org/stable/c/d0be0516b5224eb5b6f42f8564a8deadb20ae16b Added Reference https://git.kernel.org/stable/c/daefd7ff159b0d1fb8c9e64430dcbe2aca1bdd09