{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "c8b75bca92cbf064b9fa125fc74a85994452e935"
            },
            {
              "fixed": "b6beee927e7f4e3142032ff91b2d0417cdddc0f6"
            },
            {
              "fixed": "cf0c4432bda37b02e7d430ff5017228ceb7caf0c"
            },
            {
              "fixed": "ee507691c18f9fee5d4751e295ab9a7ff31d59ae"
            },
            {
              "fixed": "7f9780df677370a19b4ec9764f13b1b82073e0d9"
            },
            {
              "fixed": "073a30d75f309812ed61af134f24ffef4107b13a"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "4.4.0"
            },
            {
              "fixed": "6.6.158"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.7.0"
            },
            {
              "fixed": "6.12.112"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.54"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.2.8"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98309.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vc4: Use managed KMS polling to fix UAF on unbind\n\nvc4_kms_load() calls drm_kms_helper_poll_init() but the driver provides\nno matching drm_kms_helper_poll_fini(). The output poll work stays\nscheduled after unbind and runs on the freed drm_device:\n\n  # modprobe vc4; rmmod vc4; sleep 10\n  BUG: KASAN: slab-use-after-free in delayed_work_timer_fn\n  BUG: KASAN: slab-use-after-free in drm_client_dev_hotplug [drm]\n  Workqueue: events output_poll_execute [drm_kms_helper]\n  Allocated by task 171: __devm_drm_dev_alloc\n  Freed by task 262 (rmmod): drm_dev_put / component_del\n\nUse drmm_kms_helper_poll_init() so polling is finalized with the device,\nas other drivers do.",
  "id": "CVE-2026-98309",
  "modified": "2026-10-08T02:30:29.099161900Z",
  "published": "2026-10-06T08:46:05.957Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/073a30d75f309812ed61af134f24ffef4107b13a"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/7f9780df677370a19b4ec9764f13b1b82073e0d9"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/b6beee927e7f4e3142032ff91b2d0417cdddc0f6"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/cf0c4432bda37b02e7d430ff5017228ceb7caf0c"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/ee507691c18f9fee5d4751e295ab9a7ff31d59ae"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98309.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-98309"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "drm/vc4: Use managed KMS polling to fix UAF on unbind"
}