Linux Kernel Vulnerability in DPLL Device Change Notifications
CVE-2026-63977

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-63977?

This vulnerability in the Linux kernel involves DPLL device change notifications, where an outdated method was previously used for handling device change notifications. The introduction of a new function, __dpll_device_change_ntf(), allows for direct handling of notifications without needing to work around a locking mechanism, thereby minimizing potential race conditions. By removing the old change_work infrastructure, the risk of dereferencing a freed or NULL pointer during device teardown is mitigated, enhancing overall system stability.

Affected Version(s)

Linux 9363b4837659d1b7ee04cfa714373ce4b4b8269f

Linux 9363b4837659d1b7ee04cfa714373ce4b4b8269f

Linux 6.18

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.