Linux Kernel GUD Rotation Property Validation Flaw (CVE-2026-98148)
CVE-2026-98148 Published on September 25, 2026
drm/gud: validate GUD_ROTATION_0 is present in supported rotations
In the Linux kernel, the following vulnerability has been resolved:
drm/gud: validate GUD_ROTATION_0 is present in supported rotations
The rotation argument to drm_plane_create_rotation_property() is set to
DRM_MODE_ROTATE_0, and the device reported rotation bitmask is used as
the supported_rotations argument. The driver never validates that
GUD_ROTATION_0 is present, so a device that omits it from its
GUD_PROPERTY_ROTATION triggers the
WARN_ON(rotation & ~supported_rotations) in
drm_plane_create_rotation_property()
Fix this by skipping the creation of rotation property if the device
doesn't have the GUD_ROTATION_0 bit
Products Associated with CVE-2026-98148
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 40e1a70b4aedf2859a1829991b48ef0ebe650bf2 and below b2cd682324b889011874cf844b7c7efa97c97296 is affected.
- Version 40e1a70b4aedf2859a1829991b48ef0ebe650bf2 and below 876b33d8a9a00e9d4bbcbb7f55ad2c05974850de is affected.
- Version 40e1a70b4aedf2859a1829991b48ef0ebe650bf2 and below cb732d027aa18e1fcf9d2797f47d20b179ebc59c is affected.
- Version 5.13 is affected.
- Before 5.13 is unaffected.
- Version 6.18.53, <= 6.18.* is unaffected.
- Version 7.2.7, <= 7.2.* is unaffected.
- Version 7.3-rc2, <= * is unaffected.