Linux Kernel Workqueue Leak Vulnerability in DRM MSM Component

Vulnerability

A vulnerability exists in the Linux kernel's DRM MSM component, where a workqueue leak can occur if an early binding error arises, such as a subcomponent failing to bind. This issue has been addressed by ensuring that the workqueue is properly destroyed in case of such errors. The vulnerability affects several versions of the Linux kernel.

Impact

The vulnerability could lead to a workqueue leak, causing memory management issues by not properly releasing resources, which could potentially be exploited to create a denial-of-service condition.

Reproduction

The vulnerability can be reproduced by causing a binding error in a subcomponent of the DRM MSM driver, which will trigger the workqueue leak by failing to properly clean up the resources before the error.

Remediation

Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for downloading the patched version are available on the official Linux kernel website.

Added: Dec 9, 2025, 9:23 PM
Updated: Dec 9, 2025, 9:23 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
4.3
remediation
7.7
relevance
1.3
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.