PT-2026-94645 · Linux · Linux Kernel

CVE-2026-90297

·

Published

2026-09-17

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the drm/sun4i component where the sun4i crtc init() function returns NULL instead of an error pointer when layer initialization fails. Because the caller function sun4i tcon bind() uses IS ERR() to validate the result, it fails to detect the NULL return and continues execution with tcon->crtc set to NULL. Subsequently, the sun4i rgb init() and sun4i lvds init() functions dereference this NULL pointer within drm crtc mask(), leading to a system crash (oops).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102332
CVE-2026-90297
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel