---
id: CVE-2026-98309
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  drm/vc4: Use managed KMS polling to fix UAF on unbind

  vc4_kms_load() calls drm_kms_helper_poll_init() but the driver provides
  no matching drm_kms_helper_poll_fini()
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  drm/vc4: Use managed KMS polling to fix UAF on unbind

  vc4_kms_load() calls drm_kms_helper_poll_init() but the driver provides
  no matching drm_kms_helper_poll_fini(). T…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= c8b75bca92cbf064b9fa125fc74a85994452e935 <
    b6beee927e7f4e3142032ff91b2d0417cdddc0f6
  - >-
    Linux >= c8b75bca92cbf064b9fa125fc74a85994452e935 <
    cf0c4432bda37b02e7d430ff5017228ceb7caf0c
  - >-
    Linux >= c8b75bca92cbf064b9fa125fc74a85994452e935 <
    ee507691c18f9fee5d4751e295ab9a7ff31d59ae
  - >-
    Linux >= c8b75bca92cbf064b9fa125fc74a85994452e935 <
    7f9780df677370a19b4ec9764f13b1b82073e0d9
  - >-
    Linux >= c8b75bca92cbf064b9fa125fc74a85994452e935 <
    073a30d75f309812ed61af134f24ffef4107b13a
  - Linux 4.4
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:22.300'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98309'
references:
  - url: 'https://git.kernel.org/stable/c/073a30d75f309812ed61af134f24ffef4107b13a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7f9780df677370a19b4ec9764f13b1b82073e0d9'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b6beee927e7f4e3142032ff91b2d0417cdddc0f6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/cf0c4432bda37b02e7d430ff5017228ceb7caf0c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ee507691c18f9fee5d4751e295ab9a7ff31d59ae'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.413Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

drm/vc4: Use managed KMS polling to fix UAF on unbind

vc4_kms_load() calls drm_kms_helper_poll_init() but the driver provides
no matching drm_kms_helper_poll_fini(). The output poll work stays
scheduled after unbind and runs on the freed drm_device:

  # modprobe vc4; rmmod vc4; sleep 10
  BUG: KASAN: slab-use-after-free in delayed_work_timer_fn
  BUG: KASAN: slab-use-after-free in drm_client_dev_hotplug [drm]
  Workqueue: events output_poll_execute [drm_kms_helper]
  Allocated by task 171: __devm_drm_dev_alloc
  Freed by task 262 (rmmod): drm_dev_put / component_del

Use drmm_kms_helper_poll_init() so polling is finalized with the device,
as other drivers do.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
