---
id: CVE-2024-53056
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  drm/mediatek: Fix potential NULL dereference in mtk_crtc_destroy()

  In mtk_crtc_create(), if the call to mbox_request_channel() fails then we
  set the "mtk_crtc->cmdq_cl…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  drm/mediatek: Fix potential NULL dereference in mtk_crtc_destroy()

  In mtk_crtc_create(), if the call to mbox_request_channel() fails then we
  set the "mtk_crtc->cmdq_cl…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-476
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 5.17, < 6.11.7'
  - linux_kernel = 6.12
patched:
  - linux_kernel 6.11.7
published: '2024-11-19'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T11:17:32.020'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-53056'
references:
  - url: 'https://git.kernel.org/stable/c/4018651ba5c409034149f297d3dd3328b91561fd'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c60583a87cb4a85b69d1f448f0be5eb6ec62cbb2'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/fb05e973698f4af008c7fb6e0cfa6a2fa1d98409'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2025-10-01T20:13:00.629293Z'
epss: 0.00206
epssPercentile: 0.09624
ingestedAt: '2026-10-03T11:43:42.104Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

drm/mediatek: Fix potential NULL dereference in mtk_crtc_destroy()

In mtk_crtc_create(), if the call to mbox_request_channel() fails then we
set the "mtk_crtc->cmdq_client.chan" pointer to NULL.  In that situation,
we do not call cmdq_pkt_create().

During the cleanup, we need to check if the "mtk_crtc->cmdq_client.chan"
is NULL first before calling cmdq_pkt_destroy().  Calling
cmdq_pkt_destroy() is unnecessary if we didn't call cmdq_pkt_create() and
it will result in a NULL pointer dereference.

## Affected

- `linux_kernel >= 5.17, < 6.11.7`
- `linux_kernel = 6.12`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.11.7`
