In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid NULL...
🔗 CVE IDs covered (1)
📋 Description
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Avoid NULL dereference in dc_dmub_srv error paths
In dc_dmub_srv_log_diagnostic_data() and dc_dmub_srv_enable_dpia_trace().
Both functions check:
if (!dc_dmub_srv || !dc_dmub_srv->dmub)
and then call DC_LOG_ERROR() inside that block.
DC_LOG_ERROR() uses dc_dmub_srv->ctx internally. So if dc_dmub_srv is NULL, the logging itself can dereference a NULL pointer and cause a crash.
Fix this by splitting the checks.
First check if dc_dmub_srv is NULL and return immediately. Then check dc_dmub_srv->dmub and log the error only when dc_dmub_srv is valid.
Fixes the below: ../display/dc/dc_dmub_srv.c:962 dc_dmub_srv_log_diagnostic_data() error: we previously assumed 'dc_dmub_srv' could be null (see line 961) ../display/dc/dc_dmub_srv.c:1167 dc_dmub_srv_enable_dpia_trace() error: we previously assumed 'dc_dmub_srv' could be null (see line 1166)
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-53313
- https://git.kernel.org/stable/c/4ae3e16f4b3bf64140f773629b765d605ee079a9
- https://git.kernel.org/stable/c/b37a978e6d8c33fbfa4abc5dcca4c7cfc6d01f22
- https://git.kernel.org/stable/c/2ab18de5ebb11c76bfc8087c5a09fbcccd0dea8a
- https://git.kernel.org/stable/c/a71fdbd6e8289e2725d33a9873833459f3b1824f
- https://github.com/advisories/GHSA-2885-rcqv-3jp6