CVE-2026-23471 — Expired Pointer Dereference in Linux
Severity
5.5MEDIUM
No vectorEPSS
No EPSS data
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 3
Description
drm: Fix use-after-free on framebuffers and property blobs when calling drm_dev_unplug
In the Linux kernel, the following vulnerability has been resolved:
drm: Fix use-after-free on framebuffers and property blobs when calling drm_dev_unplug
When trying to do a rather aggressive test of igt's "xe_module_load
--r reload" with a full desktop environment and game running I noticed
a few OOPSes when dereferencing freed pointers, related to
framebuffers and property blobs after the compositor exit…
Affected Packages3 packages
▶CVEListV5linux/linuxbee330f3d67273a68dcb99f59480d59553c008b2 — 54df178324b268c62f847381e2813a1b0f971384+6
🔴Vulnerability Details
3GHSA▶
GHSA-9h7x-8rrr-c9c7: In the Linux kernel, the following vulnerability has been resolved:
drm: Fix use-after-free on framebuffers and property blobs when calling drm_dev_u↗2026-04-03
OSV▶
CVE-2026-23471: In the Linux kernel, the following vulnerability has been resolved: drm: Fix use-after-free on framebuffers and property blobs when calling drm_dev_un↗2026-04-03
CVEList
▶
📋Vendor Advisories
2🕵️Threat Intelligence
1💬Community
1Bugzilla▶
CVE-2026-23471 kernel: drm: Fix use-after-free on framebuffers and property blobs when calling drm_dev_unplug↗2026-04-03