HIGHVulnerability

CVE-2026-64050

In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: don't mix devm and drmm functions Mixing devm and drmm functions will result in a use-after-free on msm driver teardown if userspace keeps a reference on the drm device: The WB connector data will be destroyed because of the use of devm_kzalloc()), while the usersoace still can try interacting with the WB connector (which uses drmm_ functions). Change dpu_writeback_init() to use drmm_. Patchwork: https://patchwork.freedesktop.org/patch/722656/

Properties

severity
HIGH
score
7.8
epss_score
0.00124
cve_id
CVE-2026-64050
vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
published_at
2026-07-19T16:17:45.413
last_modified
2026-09-02T21:10:22.507
epss_percentile
0.02388

Related Entities (8)

ENRICHED_BY (1)

[Source]FIRST EPSS

AFFECTS_PRODUCT (5)

[Product]
[Product]
[Product]
[Product]
[Product]

HAS_WEAKNESS (1)

[Weakness]Use After Free

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-64050 — Ninja Signal Threat Intelligence | Ninja Signal