{"id":"CVE-2026-68236","title":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: set new_stream to NULL after release\n\nIn dm_update_crtc_state(), the skip_modeset path releases new_stream\nvia dc_stream_release() but does not set the…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: set new_stream to NULL after release\n\nIn dm_update_crtc_state(), the skip_modeset path releases new_stream\nvia dc_stream_release() but does not set the…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","vendor":"Linux","product":"Linux","affected":["Linux >= 9b690ef3c70422cdcd0cf912db33f2c92ef4a53f < 92b7c6e3a1546c6db868b07e93fa6fb950d1d3a0","Linux >= 9b690ef3c70422cdcd0cf912db33f2c92ef4a53f < bf9c06c70f496f1ba4474caf95c69696c828340e","Linux >= 9b690ef3c70422cdcd0cf912db33f2c92ef4a53f < 01ba5b36898d6258f584269537cc49e7b05cf7c6","Linux >= 9b690ef3c70422cdcd0cf912db33f2c92ef4a53f < ba8bf1dcbb44773e7a0fd13b42925c644e0d5e76","Linux >= 9b690ef3c70422cdcd0cf912db33f2c92ef4a53f < 5182e442e61397d446c36995b8f5676942d35b82","Linux >= 9b690ef3c70422cdcd0cf912db33f2c92ef4a53f < 679f23f0a3606afcef1ffabd72222f00a54ad9e3","Linux >= 9b690ef3c70422cdcd0cf912db33f2c92ef4a53f < 0676fecbb5242aa22c057e78326d6d6041db034c","Linux >= 9b690ef3c70422cdcd0cf912db33f2c92ef4a53f < 9fa26b9eed6195bf840f39ac183b9a6237548755","Linux 4.15"],"published":"2026-08-10","updated":"2026-10-03","sourceUpdated":"2026-10-03T11:17:36.130","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-68236","references":[{"url":"https://git.kernel.org/stable/c/01ba5b36898d6258f584269537cc49e7b05cf7c6","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0676fecbb5242aa22c057e78326d6d6041db034c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5182e442e61397d446c36995b8f5676942d35b82","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/679f23f0a3606afcef1ffabd72222f00a54ad9e3","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/92b7c6e3a1546c6db868b07e93fa6fb950d1d3a0","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9fa26b9eed6195bf840f39ac183b9a6237548755","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ba8bf1dcbb44773e7a0fd13b42925c644e0d5e76","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bf9c06c70f496f1ba4474caf95c69696c828340e","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"epss":0.0017,"epssPercentile":0.05741,"ingestedAt":"2026-10-03T11:43:42.116Z","slug":"CVE-2026-68236","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: set new_stream to NULL after release\n\nIn dm_update_crtc_state(), the skip_modeset path releases new_stream\nvia dc_stream_release() but does not set the pointer to NULL.\n\nIf a later error (e.g., color management failure) triggers the fail\nlabel, the error path calls dc_stream_release() again on the same\ndangling pointer, causing a double release and potential use-after-free.\n\nFix this by setting new_stream to NULL after the initial release.\n\n(cherry picked from commit 99f3af19073b3ddbfd96e789124cce12c4277b28)\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}