CVE-2026-98309: drm/vc4: Use managed KMS polling to fix UAF on unbind
drm/vc4: Use managed KMS polling to fix UAF on unbind
drm/vc4: Use managed KMS polling to fix UAF on unbind
The issue is triggered when the vc4 kernel module is unloaded after it has initialized KMS polling. The documented reproduction is loading vc4, removing it with rmmod vc4, and then waiting for the still-scheduled output polling work to run.
The available information describes a local kernel-module unload scenario and does not identify any remote attack vector. Exploitation requires the vc4 driver to be loaded and then unbound or removed while its polling work remains scheduled.
Systems may report KASAN slab-use-after-free errors after vc4 is removed, including reports involving delayed_work_timer_fn or drm_client_dev_hotplug. The affected work may appear on the events workqueue as output_poll_execute from drm_kms_helper.
Avoid unloading or unbinding the vc4 driver after it has been loaded. The defect occurs because output polling remains scheduled after device teardown.