Answer in brief
CVE-2026-90297 records a Unknown severity vulnerability in drm/sun4i: crtc: Propagate layer initialization error. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=dcd215801b0279f0a021516526cf7c0b67d5302e <aaf812960fb5ade24be7a1d8fea27a1ffc458c30 || >=dcd215801b0279f0a021516526cf7c0b67d5302e <e216d6168f25a69e5ae5b981ee73b3a860a46441 || >=dcd215801b0279f0a021516526cf7c0b67d5302e <2bb3169788f8296c8fc1e0d4fa6f1c6367cd5829 || >=dcd215801b0279f0a021516526cf7c0b67d5302e <1882112124a642de7571fbf354fa1929decbb3ef || >=dcd215801b0279f0a021516526cf7c0b67d5302e <8f32af44d43332c02198752e596df00659bf4354 || >=dcd215801b0279f0a021516526cf7c0b67d5302e <65bc02fec98e4e1d7d59d86cf2ddf8fd73dacb89 || >=dcd215801b0279f0a021516526cf7c0b67d5302e <c0d3219ffd4c0d42295e0dc949856067b7818b71 || >=dcd215801b0279f0a021516526cf7c0b67d5302e <7061ff05ed4a3cf16e83f7e3ad09cbd212508a32 | aaf812960fb5ade24be7a1d8fea27a1ffc458c30, e216d6168f25a69e5ae5b981ee73b3a860a46441, 2bb3169788f8296c8fc1e0d4fa6f1c6367cd5829, 1882112124a642de7571fbf354fa1929decbb3ef, 8f32af44d43332c02198752e596df00659bf4354, 65bc02fec98e4e1d7d59d86cf2ddf8fd73dacb89, c0d3219ffd4c0d42295e0dc949856067b7818b71, 7061ff05ed4a3cf16e83f7e3ad09cbd212508a32 |
| Linux/Linuxgeneric | 4.12 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: drm/sun4i: crtc: Propagate layer initialization error sun4i_crtc_init() returns plain NULL when layer initialization fails, while all its other error paths return an error pointer. The only caller, sun4i_tcon_bind(), checks the result with IS_ERR() and happily continues with tcon->crtc set to NULL. sun4i_rgb_init() and sun4i_lvds_init() then dereference it in drm_crtc_mask(), which oopses. Return the error pointer instead.
Quoted source text, attributed separately from HOL analysis.