In the Linux kernel, the following vulnerability has been resolved:
drm/exynos: vidi: use ctx->lock to protect struct vidi_context member variables related to memory alloc/free
Exynos Virtual Display driver performs memory alloc/free operations
without lock protection, which easily causes concurrency problem.
For example, use-after-free can occur in race scenario like this:
```
CPU0 CPU1 CPU2
---- ---- ----
vidi_connection_ioctl()
if (vidi->connection) // true
drm_edid = drm_edid_alloc(); // alloc drm_edid
...
ctx->raw_edid = drm_edid;
...
drm_mode_getconnector()
drm_helper_probe_single_connector_modes()
vidi_get_modes()
if (ctx->raw_edid) // true
drm_edid_dup(ctx->raw_edid);
if (!drm_edid) // false
...
vidi_connection_ioctl()
if (vidi->connection) // false
drm_edid_free(ctx->raw_edid); // free drm_edid
...
drm_edid_alloc(drm_edid->edid)
kmemdup(edid); // UAF!!
...
```
To prevent these vulns, at least in vidi_context, member variables related
to memory alloc/free should be protected with ctx->lock.
References
Configurations
Configuration 1 (hide)
|
History
25 Mar 2026, 11:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
18 Mar 2026, 14:40
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
| CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | |
| References | () https://git.kernel.org/stable/c/0cd2c155740dbd00868ac5a8ae5d14cd6b9ed385 - Patch | |
| References | () https://git.kernel.org/stable/c/52b330799e2d6f825ae2bb74662ec1b10eb954bb - Patch | |
| References | () https://git.kernel.org/stable/c/60b75407c172e1f341a8a5097c5cbc97dbbdd893 - Patch | |
| References | () https://git.kernel.org/stable/c/abfdf449fb3d7b42e85a1ad1c8694b768b1582f4 - Patch | |
| First Time |
Linux
Linux linux Kernel |
|
| CWE | CWE-416 |
13 Mar 2026, 19:54
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
23 Feb 2026, 04:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| Summary |
|
18 Feb 2026, 16:22
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-18 16:22
Updated : 2026-03-25 11:16
NVD link : CVE-2026-23227
Mitre link : CVE-2026-23227
CVE.ORG link : CVE-2026-23227
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-416
Use After Free
