Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98319— drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: drm: 修复 out_fence_ptr 错误路径中 drm_pending_vblank_event 的资源泄漏问题 当提供了 out_fence_ptr 但未设置 DRM_MODE_PAGE_FLIP_EVENT 标志时,系统会分配一个 drm_pending_vblank_event 结构体。如果后续在 setup_out_fence() 过程中发生分配失败或其他错误,该事件结构体的 base.fence 字段将不会被设置,并且无法在 complete_signal

AI Predicted 5.5 Difficulty: Moderate EPSS 0.18% · P7

Possible ATT&CK Techniques 1 AI

T1562

Affected Version Matrix 20

VendorProduct Version RangeStatus
Linux Linux 92c715fca907686f5298220ece53423e38ba3aed< 3d6576ed3de01e8a378397b7020e33ae3d40aa6c affected
92c715fca907686f5298220ece53423e38ba3aed< 86c33f740aa27e9cdc1259f0cc59c9c58f545e4b affected
92c715fca907686f5298220ece53423e38ba3aed< 88c450e23b8fd4f1dcd329562f5e81ef05f3d941 affected
92c715fca907686f5298220ece53423e38ba3aed< 780716e2e019186fa6e5aad097a44b87b0b5388f affected
92c715fca907686f5298220ece53423e38ba3aed< d0be0516b5224eb5b6f42f8564a8deadb20ae16b affected
92c715fca907686f5298220ece53423e38ba3aed< daefd7ff159b0d1fb8c9e64430dcbe2aca1bdd09 affected
92c715fca907686f5298220ece53423e38ba3aed< b9a68a9ccaada15d8dd0102c188cc6b868ff800b affected
92c715fca907686f5298220ece53423e38ba3aed< 9eb1a393c89a79c4210230d23e7d88d239c61d7b affected
… +12 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98319

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr When an out_fence_ptr is provided but DRM_MODE_PAGE_FLIP_EVENT is not set, a drm_pending_vblank_event will be allocated. If later, there is an allocation failure or another failure at setup_out_fence(), that event will not have base.fence set and it will not be released at complete_signaling(). Release the event and set crtc_state->event to NULL just like in the DRM_MODE_PAGE_FLIP_EVENT case when there is a failure at drm_event_reserve_init(). That is, prepare_signaling() releases the event and there is nothing to be done at complete_signaling(). Use drm_event_cancel_free() as that will also undo drm_event_reserve_init() in case it has been called.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 92c715fca907686f5298220ece53423e38ba3aed ~ 3d6576ed3de01e8a378397b7020e33ae3d40aa6c -
Linux Linux 4.10 -

II. Public POCs for CVE-2026-98319

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98319

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98319 (8)

Same Patch Batch · Linux · 2026-10-06 · 208 CVEs total

CVE-2026-98323 9.8 CRITICAL RDMA/siw: Bound fragmented header copies by the remaining length
CVE-2026-98365 9.8 CRITICAL RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
CVE-2026-98282 8.8 HIGH powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
CVE-2026-98283 8.8 HIGH KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
CVE-2026-98339 8.8 HIGH wifi: cfg80211: don't filter by BSS type when removing stale entries
CVE-2026-98171 8.8 HIGH smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
CVE-2026-98261 8.1 HIGH cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
CVE-2026-98357 8.1 HIGH IB/isert: wait for deferred control PDU completions before releasing the connection
CVE-2026-98239 8.1 HIGH net: lan743x: fix RX checksum use-after-free
CVE-2026-98305 7.8 HIGH net: dsa: mxl862xx: disable the stats poll on teardown
CVE-2026-98341 7.8 HIGH wifi: cfg80211: don't free driver-owned scan requests
CVE-2026-98320 7.8 HIGH netfilter: flowtable: hold reference on ct until flow is released
CVE-2026-98228 7.8 HIGH mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
CVE-2026-98229 7.8 HIGH xfrm: save input state data before secpath resets
CVE-2026-98318 7.8 HIGH smb: client: validate absolute native symlink targets before NT fixups
CVE-2026-98315 7.8 HIGH ntfs: protect runlist updates with the runlist lock
CVE-2026-98311 7.8 HIGH wifi: virt_wifi: don't transfer operstate before register
CVE-2026-98276 7.8 HIGH net: lock the socket in sock_gettstamp()
CVE-2026-98258 7.8 HIGH posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
CVE-2026-98260 7.8 HIGH exec: Cleanup POSIX timers right after de_thread()

Showing top 20 of 208 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98319

No comments yet


Leave a comment