CVE-2026-53347
In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Fix driver removal with disabled KMS DRM atomic and modesetting aren't initialized if virtio-gpu driver built with disabled KMS, leading to access of uninitialized data on…
Does this matter?
Lower severity and a low EPSS score (0.16%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Fix driver removal with disabled KMS DRM atomic and modesetting aren't initialized if virtio-gpu driver built with disabled KMS, leading to access of uninitialized data on driver removal/unbinding and crashing kernel. Fix it by skipping shutting down atomic core with unavailable KMS.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.16% probability · 6th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-908
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/15e561869a8b4e4db69733be1d6f33770664f989Patch
- https://git.kernel.org/stable/c/19a6a00ff50c284f3a9818882ad2be58b33b790aPatch
- https://git.kernel.org/stable/c/38a5f891cda6d121c149c94cda89c31ec7024ee3Patch
- https://git.kernel.org/stable/c/ed3e134700a2e07caa99b9bc0683ebbe0327c562Patch
- https://git.kernel.org/stable/c/f329e8325e054bd6d84d10904f8dd51137281b92Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.