CVE-2026-45956 Details
Description
In the Linux kernel, the following vulnerability has been resolved: drm/exynos: vidi: use priv->vidi_dev for ctx lookup in vidi_connection_ioctl() vidi_connection_ioctl() retrieves the driver_data from drm_dev->dev to obtain a struct vidi_context pointer. However, drm_dev->dev is the exynos-drm master device, and the driver_data contained therein is not the vidi component device, but a completely different device. This can lead to various bugs, ranging from null pointer dereferences and garbage value accesses to, in unlucky cases, out-of-bounds errors, use-after-free errors, and more. To resolve this issue, we need to store/delete the vidi device pointer in exynos_drm_private->vidi_dev during bind/unbind, and then read this exynos_drm_private->vidi_dev within ioctl() to obtain the correct struct vidi_context pointer.
A vulnerability exists in the Linux kernel's handling of the VIDI component within the Exynos DRM subsystem. The issue arises in the 'vidi_connection_ioctl()' function, which incorrectly retrieves the VIDI context from the master DRM device instead of the specific VIDI component device. This misallocation can lead to various errors, including null pointer dereferences, access to invalid memory, out-of-bounds errors, and use-after-free vulnerabilities. The problem has been addressed by modifying the driver to store and retrieve the correct VIDI device pointer during the binding process, ensuring that the appropriate context is accessed during IOCTL operations.
The vulnerability has been fixed in the Linux kernel. Users should upgrade to the latest version where this issue has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/21ca24ba51a2c28bcc4df9d7e5a40b0eb66ab76d | kernel.org | Patch |
| https://git.kernel.org/stable/c/2987642c5213508c6c9e718324c0d5289a92c474 | kernel.org | Patch |
| https://git.kernel.org/stable/c/65d1213baffa363f2eb1117b1dc7acc573b890f8 | kernel.org | Patch |
| https://git.kernel.org/stable/c/875fa28690e93ed5296c31d3344556c6bb867234 | kernel.org | Patch |
| https://git.kernel.org/stable/c/a540f767642f75240a6c35f6a65b69e44cfcea9d | kernel.org | Patch |
| https://git.kernel.org/stable/c/b5fc86d753dd4c281a943b92f0eef02d31af03d7 | kernel.org | Patch |
| https://git.kernel.org/stable/c/d3968a0d85b211e197f2f4f06268a7031079e0d0 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.3, < 5.10.253 >= 5.11, < 5.15.203 >= 5.16, < 6.1.167 >= 6.2, < 6.6.130 >= 6.7, < 6.18.14 >= 6.19, < 6.19.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 16, 2026 | Initial Analysis | [email protected] |
| Jun 5, 2026 | CVE Modified | kernel.org |
| May 27, 2026 | New CVE Received | kernel.org |