Unrated severityNVD Advisory· Published Feb 14, 2026
drm: Do not allow userspace to trigger kernel warnings in drm_gem_change_handle_ioctl()
CVE-2026-23149
Description
In the Linux kernel, the following vulnerability has been resolved:
drm: Do not allow userspace to trigger kernel warnings in drm_gem_change_handle_ioctl()
Since GEM bo handles are u32 in the uapi and the internal implementation uses idr_alloc() which uses int ranges, passing a new handle larger than INT_MAX trivially triggers a kernel warning:
idr_alloc(): ... if (WARN_ON_ONCE(start < 0)) return -EINVAL; ...
Fix it by rejecting new handles above INT_MAX and at the same time make the end limit calculation more obvious by moving into int domain.
Affected products
2- Linux/Linuxv5Range: 6.18
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.