In the Linux kernel, the following vulnerability has been resolved:
drm: Do not allow userspace to trigger kernel warnings in drm_gem_change_handle_ioctl()
Since GEM bo handles are u32 in the uapi and the internal implementation
uses idr_alloc() which uses int ranges, passing a new handle larger than
INT_MAX trivially triggers a kernel warning:
idr_alloc():
...
if (WARN_ON_ONCE(start < 0))
return -EINVAL;
...
Fix it by rejecting new handles above INT_MAX and at the same time make
the end limit calculation more obvious by moving into int domain.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-02-14 16:15
Updated : 2026-06-17 10:20
NVD link : CVE-2026-23149
Mitre link : CVE-2026-23149
CVE.ORG link : CVE-2026-23149
JSON object : View
Products Affected
linux
- linux_kernel
CWE
