{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90316","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.801Z","datePublished":"2026-09-17T16:08:34.875Z","dateUpdated":"2026-09-18T17:54:31.233Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:54:31.233Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/omap: dsi: Do not copy isr table\n\nTo be able to unregister stuff from isrs, the corresponding table was\ncopied.  Nobody seems to unregister stuff that way, so it does not help.\nBut there are stack-allocated objects passed to these isrs giving chances\nof UAF of these objects if irqs are unregistered while they are handled,\nso better do not copy that table."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The UAF is reached from local DRM_IOCTL_MODE_ATOMIC on /dev/dri/card*: dsi_bridge_disable()→dsi_disable()→dsi_sync_vc(), or a command-mode pageflip via omap_crtc_flush()→dsi_update_channel()→_dsi_send_nop()→dsi_vc_send_bta_sync(). Those register stack objects that omap_dsi_irq_handler() later fires from isr_tables_copy; no remote protocol carries this.\nAC:L - The attacker repeats those commits/pageflips so dsi_vc_send_bta_sync()/dsi_sync_vc_vp() register a stack completion then dsi_unregister_isr_vc() after wait_for_completion_timeout(), while DSI BTA/PACKET_SENT IRQs run omap_dsi_irq_handler() on another CPU against the copied table; both sides of the copy-vs-unregister race are attacker-driven.\nPR:L - DRM_IOCTL_MODE_ATOMIC is gated by DRM_MASTER in drm_ioctl_permit(), not CAP_SYS_ADMIN. drm_master_open() makes the first opener of an unclaimed omapdrm card the master, and a seat/video-group user on AM57x/OMAP DSI hardware typically holds that; this is ordinary local privilege, not init-namespace root.\nUI:N - The attacker opens /dev/dri/card* and submits their own atomic commits or dirty/page-flip ioctls that call dsi_vc_send_bta_sync() or dsi_sync_vc(); no other user must mount media, confirm a prompt, or attach a panel.\nS:U - dsi_call_isrs() running dsi_completion_handler()/dsi_packet_sent_handler_vp() corrupts kernel stack in the same kernel that hosts omapdrm; this is local kernel memory corruption, not a VM, IOMMU, or sandbox-boundary escape.\nC:H - dsi_call_isrs() invokes dsi_packet_sent_handler_vp/l4 with isr_data->arg still pointing at a returned dsi_packet_sent_handler_data / DECLARE_COMPLETION_ONSTACK frame; after reuse that object is read as a fake dsi pointer through dsi_read_reg()/REG_GET, which is a UAF read of kernel memory.\nI:H - The same dangling arg is passed to complete() in dsi_completion_handler and to complete(vp_data->completion) in the packet-sent handlers; a reused stack slot that overwrites the completion pointer lets complete() lock and wake a wait-queue at an attacker-influenced address, a kernel write/control-flow hijack.\nA:H - complete() on a freed stack completion, or dsi_read_reg() through a dangling dsi_data in dsi_packet_sent_handler_vp, oopses or panics the kernel even if the UAF is not turned into a full write primitive."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/omapdrm/dss/dsi.c","drivers/gpu/drm/omapdrm/dss/dsi.h"],"versions":[{"version":"4ae2ddddf44cd9f73def2dbdb68c6859072262ff","lessThan":"b3cbd1451c240446ce170f514244e1cb65ec0de4","status":"affected","versionType":"git"},{"version":"4ae2ddddf44cd9f73def2dbdb68c6859072262ff","lessThan":"f6733460b6d483dea7bfb5cfceb11cbff31a60b7","status":"affected","versionType":"git"},{"version":"4ae2ddddf44cd9f73def2dbdb68c6859072262ff","lessThan":"542a6a3ec77cd29f953987f7263f32fb8acb097e","status":"affected","versionType":"git"},{"version":"4ae2ddddf44cd9f73def2dbdb68c6859072262ff","lessThan":"2c27a84ba8d1bfed046d0067161d92001605accc","status":"affected","versionType":"git"},{"version":"4ae2ddddf44cd9f73def2dbdb68c6859072262ff","lessThan":"9063b30faae8ccaacf003735560df3956dbb592f","status":"affected","versionType":"git"},{"version":"4ae2ddddf44cd9f73def2dbdb68c6859072262ff","lessThan":"30810bdf273b4c93f8731b96a7204f33e052180d","status":"affected","versionType":"git"},{"version":"4ae2ddddf44cd9f73def2dbdb68c6859072262ff","lessThan":"97c03b32b28a9f7f13f768f2b06e1eaafe850e66","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/omapdrm/dss/dsi.c","drivers/gpu/drm/omapdrm/dss/dsi.h"],"versions":[{"version":"2.6.39","status":"affected"},{"version":"0","lessThan":"2.6.39","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.39","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.39","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.39","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.39","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.39","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.39","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.39","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/b3cbd1451c240446ce170f514244e1cb65ec0de4"},{"url":"https://git.kernel.org/stable/c/f6733460b6d483dea7bfb5cfceb11cbff31a60b7"},{"url":"https://git.kernel.org/stable/c/542a6a3ec77cd29f953987f7263f32fb8acb097e"},{"url":"https://git.kernel.org/stable/c/2c27a84ba8d1bfed046d0067161d92001605accc"},{"url":"https://git.kernel.org/stable/c/9063b30faae8ccaacf003735560df3956dbb592f"},{"url":"https://git.kernel.org/stable/c/30810bdf273b4c93f8731b96a7204f33e052180d"},{"url":"https://git.kernel.org/stable/c/97c03b32b28a9f7f13f768f2b06e1eaafe850e66"}],"title":"drm/omap: dsi: Do not copy isr table","x_generator":{"engine":"bippy-1.2.0"}}}}