CVE-2026-23366
published 2026-03-25CVE-2026-23366: In the Linux kernel, the following vulnerability has been resolved: drm/client: Do not destroy NULL modes 'modes' in drm_client_modeset_probe may fail to…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.2th percentile
In the Linux kernel, the following vulnerability has been resolved:
drm/client: Do not destroy NULL modes
'modes' in drm_client_modeset_probe may fail to kcalloc. If this
occurs, we jump to 'out', calling modes_destroy on it, which
dereferences it. This may result in a NULL pointer dereference in the
error case. Prevent that.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.19.8-1 (forky) | linux 6.19.8-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= 3039cc0c0653c6e15130a8719c3237329a954670 < 4e3ca5f82346cc23c0a71f1ceb006115ff6b0745 | 4e3ca5f82346cc23c0a71f1ceb006115ff6b0745 |
| linux | linux | >= 3039cc0c0653c6e15130a8719c3237329a954670 < 9aa3e33f0c7f2679ac599a09e3102c8f716a6321 | 9aa3e33f0c7f2679ac599a09e3102c8f716a6321 |
| linux | linux | >= 3039cc0c0653c6e15130a8719c3237329a954670 < c601fd5414315fc515f746b499110e46272e7243 | c601fd5414315fc515f746b499110e46272e7243 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.19.8-1 | 6.19.8-1 |
| linux | linux_kernel | >= 6.16.0 < 6.18.17 | 6.18.17 |
| linux | linux_kernel | >= 6.16.1 < 6.18.17 | 6.18.17 |
| linux | linux_kernel | >= 6.19 < 6.19.7 | 6.19.7 |
| linux | linux_kernel | >= 6.19.0 < 6.19.7 | 6.19.7 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
drm/client: Do not destroy NULL modes
osv·2026-03-25
CVE-2026-23366 drm/client: Do not destroy NULL modes
drm/client: Do not destroy NULL modes
In the Linux kernel, the following vulnerability has been resolved:
drm/client: Do not destroy NULL modes
'modes' in drm_client_modeset_probe may fail to kcalloc. If this
occurs, we jump to 'out', calling modes_destroy on it, which
dereferences it. This may result in a NULL pointer dereference in the
error case. Prevent that.
GHSA
GHSA-m3rw-wqqm-pcwv: In the Linux kernel, the following vulnerability has been resolved:
drm/client: Do not destroy NULL modes
'modes' in drm_client_modeset_probe may fa
ghsa_unreviewed·2026-03-25
CVE-2026-23366 GHSA-m3rw-wqqm-pcwv: In the Linux kernel, the following vulnerability has been resolved:
drm/client: Do not destroy NULL modes
'modes' in drm_client_modeset_probe may fa
In the Linux kernel, the following vulnerability has been resolved:
drm/client: Do not destroy NULL modes
'modes' in drm_client_modeset_probe may fail to kcalloc. If this
occurs, we jump to 'out', calling modes_destroy on it, which
dereferences it. This may result in a NULL pointer dereference in the
error case. Prevent that.
OSV
CVE-2026-23366: In the Linux kernel, the following vulnerability has been resolved: drm/client: Do not destroy NULL modes 'modes' in drm_client_modeset_probe may fail
osv·2026-03-25
CVE-2026-23366 CVE-2026-23366: In the Linux kernel, the following vulnerability has been resolved: drm/client: Do not destroy NULL modes 'modes' in drm_client_modeset_probe may fail
In the Linux kernel, the following vulnerability has been resolved: drm/client: Do not destroy NULL modes 'modes' in drm_client_modeset_probe may fail to kcalloc. If this occurs, we jump to 'out', calling modes_destroy on it, which dereferences it. This may result in a NULL pointer dereference in the error case. Prevent that.
Red Hat
kernel: drm/client: Do not destroy NULL modes
vendor_redhat·2026-03-25·CVSS 5.5
CVE-2026-23366 [LOW] CWE-824 kernel: drm/client: Do not destroy NULL modes
kernel: drm/client: Do not destroy NULL modes
In the Linux kernel, the following vulnerability has been resolved:
drm/client: Do not destroy NULL modes
'modes' in drm_client_modeset_probe may fail to kcalloc. If this
occurs, we jump to 'out', calling modes_destroy on it, which
dereferences it. This may result in a NULL pointer dereference in the
error case. Prevent that.
A flaw was found in the Linux kernel's Direct Rendering Manager (DRM) client component. This vulnerability occurs when the system attempts to destroy an uninitialized memory pointer, specifically the 'modes' variable within the `drm_client_modeset_probe` function, after a memory allocation failure. This can lead to a NULL pointer dereference, potentially causing system instability or a denial of service.
Package: kernel
Debian
CVE-2026-23366: linux - In the Linux kernel, the following vulnerability has been resolved: drm/client:...
vendor_debian·2026
CVE-2026-23366 [LOW] CVE-2026-23366: linux - In the Linux kernel, the following vulnerability has been resolved: drm/client:...
In the Linux kernel, the following vulnerability has been resolved: drm/client: Do not destroy NULL modes 'modes' in drm_client_modeset_probe may fail to kcalloc. If this occurs, we jump to 'out', calling modes_destroy on it, which dereferences it. This may result in a NULL pointer dereference in the error case. Prevent that.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.19.8-1)
sid: resolved (fixed in 6.19.8-1)
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-23366 kernel: drm/client: Do not destroy NULL modes
bugzilla·2026-03-25·CVSS 5.5
CVE-2026-23366 [MEDIUM] CVE-2026-23366 kernel: drm/client: Do not destroy NULL modes
CVE-2026-23366 kernel: drm/client: Do not destroy NULL modes
In the Linux kernel, the following vulnerability has been resolved:
drm/client: Do not destroy NULL modes
'modes' in drm_client_modeset_probe may fail to kcalloc. If this
occurs, we jump to 'out', calling modes_destroy on it, which
dereferences it. This may result in a NULL pointer dereference in the
error case. Prevent that.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026032540-CVE-2026-23366-a7c4@gregkh/T
Wiz
CVE-2026-23366 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2026-23366 CVE-2026-23366 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23366 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
drm/client: Do not destroy NULL modes
'modes' in drm_client_modeset_probe may fail to kcalloc. If this
occurs, we jump to 'out', calling modes_destroy on it, which
dereferences it. This may result in a NULL pointer dereference in the
error case. Prevent that.
Source : NVD
Published March 25, 2026
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
kernel
kernel-64k-modules-extra
Sources
NVD
Debian 14 Has Fix Added at
2026-03-25
Published