CVE-2026-90297

medium

Description

In the Linux kernel, the following vulnerability has been resolved: drm/sun4i: crtc: Propagate layer initialization error sun4i_crtc_init() returns plain NULL when layer initialization fails, while all its other error paths return an error pointer. The only caller, sun4i_tcon_bind(), checks the result with IS_ERR() and happily continues with tcon->crtc set to NULL. sun4i_rgb_init() and sun4i_lvds_init() then dereference it in drm_crtc_mask(), which oopses. Return the error pointer instead.

References

https://git.kernel.org/stable/c/e216d6168f25a69e5ae5b981ee73b3a860a46441

https://git.kernel.org/stable/c/c0d3219ffd4c0d42295e0dc949856067b7818b71

https://git.kernel.org/stable/c/aaf812960fb5ade24be7a1d8fea27a1ffc458c30

https://git.kernel.org/stable/c/8f32af44d43332c02198752e596df00659bf4354

https://git.kernel.org/stable/c/7061ff05ed4a3cf16e83f7e3ad09cbd212508a32

https://git.kernel.org/stable/c/65bc02fec98e4e1d7d59d86cf2ddf8fd73dacb89

https://git.kernel.org/stable/c/2bb3169788f8296c8fc1e0d4fa6f1c6367cd5829

https://git.kernel.org/stable/c/1882112124a642de7571fbf354fa1929decbb3ef

Details

Source: Mitre, NVD

Published: 2026-09-17

Updated: 2026-09-17

Risk Information

CVSS v2

Base Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00211