In the Linux kernel, the following vulnerability has been resolved: drm/colorop: Fix blob property reference tracking in state lifecycle The colorop… (CVE-2026-53378)
A memory leak vulnerability in the Linux kernel's drm/colorop component was fixed. The issue involved improper reference counting and cleanup of blob properties during state duplication, destruction, and reset operations, leading to memory leaks. The fix aligns the implementation with the established drm_crtc pattern to ensure proper lifecycle management of blob references.
AI Analysis
Technical Summary
The Linux kernel's drm/colorop subsystem had a vulnerability related to improper handling of blob property references in the state lifecycle. Specifically, drm_colorop_atomic_destroy_state() freed state memory without releasing blob references, drm_colorop_reset() freed old state memory directly instead of using the proper destruction method, and drm_colorop_cleanup() contained duplicate blob cleanup code. These issues caused memory leaks (CWE-401). The fix introduced a helper function __drm_atomic_helper_colorop_destroy_state() to correctly release blob references before freeing state memory and updated related functions to use this helper, matching the well-tested drm_crtc pattern since 2016.
Potential Impact
The vulnerability causes memory leaks in the kernel's drm/colorop state management, which can degrade system stability or availability over time. There is no impact on confidentiality or integrity. The CVSS vector indicates local attack complexity with low privileges required and no user interaction, but the impact is limited to availability due to memory leaks.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The fix involves proper reference counting and cleanup in the drm/colorop subsystem. Until an official patch is confirmed, users should monitor vendor advisories for updates and apply patches once available.
In the Linux kernel, the following vulnerability has been resolved: drm/colorop: Fix blob property reference tracking in state lifecycle The colorop… (CVE-2026-53378)
Description
A memory leak vulnerability in the Linux kernel's drm/colorop component was fixed. The issue involved improper reference counting and cleanup of blob properties during state duplication, destruction, and reset operations, leading to memory leaks. The fix aligns the implementation with the established drm_crtc pattern to ensure proper lifecycle management of blob references.
CVSS v3.1
Score 5.5medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel's drm/colorop subsystem had a vulnerability related to improper handling of blob property references in the state lifecycle. Specifically, drm_colorop_atomic_destroy_state() freed state memory without releasing blob references, drm_colorop_reset() freed old state memory directly instead of using the proper destruction method, and drm_colorop_cleanup() contained duplicate blob cleanup code. These issues caused memory leaks (CWE-401). The fix introduced a helper function __drm_atomic_helper_colorop_destroy_state() to correctly release blob references before freeing state memory and updated related functions to use this helper, matching the well-tested drm_crtc pattern since 2016.
Potential Impact
The vulnerability causes memory leaks in the kernel's drm/colorop state management, which can degrade system stability or availability over time. There is no impact on confidentiality or integrity. The CVSS vector indicates local attack complexity with low privileges required and no user interaction, but the impact is limited to availability due to memory leaks.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The fix involves proper reference counting and cleanup in the drm/colorop subsystem. Until an official patch is confirmed, users should monitor vendor advisories for updates and apply patches once available.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-2r25-qjcv-hr44
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-53378"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- 3.1
Threat ID: 6a5d27ad2a4a8d59891325dc
Added to database: 07/19/2026, 19:38:21 UTC
Last enriched: 07/30/2026, 12:03:43 UTC
Last updated: 09/03/2026, 22:52:12 UTC
Views: 84
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.