Back

HIGH

drm/i915: clear CRTC color blob pointers after dropping refs

Published Aug 15, 2026

Description

intel_crtc_put_color_blobs() drops the CRTC color blob references, but leaves the corresponding pointers unchanged.

This can matter in intel_crtc_prepare_cleared_state(), which frees the old CRTC hw state before calling intel_dp_tunnel_atomic_clear_stream_bw(). The latter can fail while looking up the DP tunnel group state, for example with -EDEADLK.

If that happens, the function returns without completing the cleared state preparation. The failed atomic state will then be cleared by the atomic core and intel_crtc_free_hw_state() can be called again for the same state, dropping the same blob references again.

Clear the blob pointers after dropping the references so repeated cleanup of the same CRTC hw state is safe.

(cherry picked from commit d5005addb5f68e8a0edce249506757bdc9e3d8c8)

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Linux
Published Aug 15, 2026
Updated Aug 17, 2026
Reserved Aug 9, 2026

CISA Vulnrichment

No data

NVD

Status Received
Modified Aug 17, 2026

Red Hat

Severity Moderate
Public date Aug 15, 2026
Bugzilla 2516568

ENISA EUVD

Assigner Linux
Published Aug 15, 2026
Updated Aug 17, 2026

GitHub

No data