← All Advisories

CVE-2026-68303

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-68303

Key Details

CVECVE-2026-68303
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

drm/vc4: hvs/v3d: Fix null dereference in unbind

The hvs and v3d drivers use dev_get_drvdata(master) in their unbind

functions. Since the vc4-drm gets removed before its dependent drivers

(vc4_hvs/vc4_v3d) the vc4_hvs_unbind/vc4_v3d_unbind functions try to

get drvdata of its master and fails with a null dereference error.

Use the data pointer passed to the unbind functions directly instead of

dev_get_drvdata(master). This avoids using potentially freed memory. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-68303
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-68303