Linux Kernel Double-Free Vulnerability in DRM XE NVM Component

Vulnerability

A double-free vulnerability has been identified in the Linux kernel's DRM XE NVM component. This issue arises during the initialization of auxiliary devices, where a failure in adding the device can trigger a release callback that frees memory. The vulnerability affects the Linux kernel stable tree, specifically in versions prior to the patch addressing this issue.

Impact

Exploitation of this vulnerability leads to a double-free condition, which can cause memory corruption and potentially allow for arbitrary code execution.

Remediation

Users can apply the patch available in the Linux kernel stable repository to address this vulnerability. Instructions for downloading the patched version can be found in the Linux kernel documentation.

Added: Feb 14, 2026, 4:20 PM
Updated: Feb 14, 2026, 4:20 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
3.8
exploitability
5.0
remediation
7.7
relevance
2.8
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.