cbcvebase.
CVE-2026-23039
published 2026-01-31

CVE-2026-23039: In the Linux kernel, the following vulnerability has been resolved: drm/gud: fix NULL fb and crtc dereferences on USB disconnect On disconnect…

PriorityP418low5.5
EPSS
0.19%
9.4th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/gud: fix NULL fb and crtc dereferences on USB disconnect On disconnect drm_atomic_helper_disable_all() is called which sets both the fb and crtc for a plane to NULL before invoking a commit. This causes a kernel oops on every display disconnect. Add guards for those dereferences.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.18.8-1 (forky)linux 6.18.8-1 (forky)
linuxlinux
linuxlinux>= 73cfd166e045769a1b42d36897accaa6e06b8102 < a255ec07f91d4c73a361a28b7a3d82f5710245f1a255ec07f91d4c73a361a28b7a3d82f5710245f1
linuxlinux>= 73cfd166e045769a1b42d36897accaa6e06b8102 < dc2d5ddb193e363187bae2ad358245642d2721fbdc2d5ddb193e363187bae2ad358245642d2721fb
linuxlinux_kernel>= 0 < 6.18.8-16.18.8-1
linuxlinux_kernel>= 6.18.0 < 6.18.76.18.7
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.