Linux Kernel Intel Graphics VRR Timing Misconfiguration Vulnerability on Certain Platforms

Vulnerability

A vulnerability in the Linux kernel's handling of Variable Refresh Rate (VRR) timings for Intel graphics can lead to system hangs on certain platforms. This issue arises when VRR timings are configured before enabling the necessary display functions, particularly on Intel Comet Lake (ICL) systems. The problem was reproduced on a Dell XPS 7390 2-in-1 laptop connected to an external display via a faulty Type-C cable, which caused the link training to fail. In contrast, Intel Tiger Lake (TGL) platforms do not exhibit this problem.

Impact

Improperly managing VRR timings can cause system hangs, particularly on Intel ICL platforms, leading to a machine check exception (MCE) and a freeze of the affected system.

Reproduction

The vulnerability can be reproduced on an Intel Comet Lake (ICL) system, such as the Dell XPS 7390 2-in-1, by connecting an external display through a Type-C dock that fails link training. This setup causes the system to hang when VRR timings are incorrectly applied before enabling the necessary display functions.

Remediation

Users can update to the latest version of the Linux kernel where this vulnerability has been addressed. Instructions for downloading the patched version are available on the official Linux kernel website.

Added: May 13, 2026, 5:37 PM
Updated: May 13, 2026, 5:37 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
2.5
remediation
7.7
relevance
8.2
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.