CVE-2026-98319: drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr
drm: Fix drmpendingvblankevent leak in error path for outfenceptr
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
In the error path for out_fence_ptr setup, use drm_event_cancel_free() to release the event and undo drm_event_reserve_init(), then set crtc_state->event to NULL.
Event History
Frequently Asked Questions
What conditions trigger the leak?
The leak occurs when an out_fence_ptr is supplied without DRM_MODE_PAGE_FLIP_EVENT and a later failure happens during setup_out_fence(), such as an allocation failure or another setup error.
What is leaked if the error path is reached?
A drm_pending_vblank_event can remain unreleased because its base.fence is not set, preventing complete_signaling() from releasing it.
What should be done if the affected error path is encountered?
The event should be released with drm_event_cancel_free(), and crtc_state->event should be set to NULL. This also undoes drm_event_reserve_init() if it was already called.