CVE-2026-43269 Details
Description
In the Linux kernel, the following vulnerability has been resolved: drm/atmel-hlcdc: fix memory leak from the atomic_destroy_state callback After several commits, the slab memory increases. Some drm_crtc_commit objects are not freed. The atomic_destroy_state callback only put the framebuffer. Use the __drm_atomic_helper_plane_destroy_state() function to put all the objects that are no longer needed. It has been seen after hours of usage of a graphics application or using kmemleak: unreferenced object 0xc63a6580 (size 64): comm "egt_basic", pid 171, jiffies 4294940784 hex dump (first 32 bytes): 40 50 34 c5 01 00 00 00 ff ff ff ff 8c 65 3a c6 @P4..........e:. 8c 65 3a c6 ff ff ff ff 98 65 3a c6 98 65 3a c6 .e:......e:..e:. backtrace (crc c25aa925): kmemleak_alloc+0x34/0x3c __kmalloc_cache_noprof+0x150/0x1a4 drm_atomic_helper_setup_commit+0x1e8/0x7bc drm_atomic_helper_commit+0x3c/0x15c drm_atomic_commit+0xc0/0xf4 drm_atomic_helper_set_config+0x84/0xb8 drm_mode_setcrtc+0x32c/0x810 drm_ioctl+0x20c/0x488 sys_ioctl+0x14c/0xc20 ret_fast_syscall+0x0/0x54
A memory leak vulnerability has been identified in the Linux kernel's Atmel HLCDC Direct Rendering Manager (DRM) module. This issue arises from the atomic_destroy_state callback, which fails to properly free certain drm_crtc_commit objects, leading to an accumulation of slab memory. The callback only releases the framebuffer, neglecting other necessary objects. The memory leak becomes apparent after prolonged use of a graphics application or through the kmemleak tool, which indicates unreferenced objects. The vulnerability has been addressed by modifying the callback to use the __drm_atomic_helper_plane_destroy_state() function, ensuring all unneeded objects are properly released.
The vulnerability has been fixed in the Linux kernel. Users should upgrade to the latest version that includes the patch.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/082271e364a3205598c2e4e6233a9f49ce7941cf | kernel.org | Patch |
| https://git.kernel.org/stable/c/25e832a7830740e72103eb0b527680a4b64bbcb3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/3e64e78f4a70e3f6ac8fe5a7071f08ffd25a2489 | kernel.org | Patch |
| https://git.kernel.org/stable/c/5718d98976ad6b9700e5a6afec67fc47a8a92580 | kernel.org | Patch |
| https://git.kernel.org/stable/c/57fa3487acfa3467405f8506b94682abd96e7393 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6d4e91ab97fda64e8cf9c8881cc3b4da026bd849 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ec40702029b08ee8d5f5b03303d64a10e74a957b | kernel.org | Patch |
| https://git.kernel.org/stable/c/f12352471061df83a36edf54bbb16284793284e4 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-401 | Missing Release of Memory after Effective Lifetime | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.1, < 5.10.252 >= 5.11, < 5.15.202 >= 5.16, < 6.1.165 >= 6.2, < 6.6.128 >= 6.7, < 6.12.75 >= 6.13, < 6.18.16 >= 6.19, < 6.19.6 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 8, 2026 | Initial Analysis | [email protected] |
| May 6, 2026 | New CVE Received | kernel.org |