
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23049 is a vulnerability in the Linux kernel's drm/panel-simple driver caused by a missing connector type for the DataImage SCF0700C48GGU18 panel. When devm_drm_panel_bridge_add() is called without a valid connector type set, it triggers a kernel warning and backtrace, resulting in the panel failing to initialize. The issue was published on February 4, 2026, and affects Linux kernel versions from the introduction of the DataImage SCF0700C48GGU18 panel entry (commit 97ceb1fb08b6) up to the respective fix commits across stable branches. The CVSS estimate is Medium severity with an EPSS score of 0.018% (Feedly, EUVD).
The root cause is an incomplete panel descriptor entry in drivers/gpu/drm/panel/panel-simple.c — the connector_type field was left unset for the DataImage SCF0700C48GGU18 panel. This falls under CWE-665 (Improper Initialization). When the DRM subsystem calls devm_drm_panel_bridge_add(), a validity check at drivers/gpu/drm/bridge/panel.c:379 (inside devm_drm_of_get_bridge) detects the missing connector type and emits a WARNING with a backtrace, preventing the panel bridge from being registered and leaving the display non-functional. The fix simply fills in the correct connector type in the panel's descriptor structure (Feedly, EUVD).
The primary impact is a denial of availability for the DataImage SCF0700C48GGU18 display panel on affected embedded Linux systems — the panel will not function, and a kernel warning with backtrace is emitted to the system log. There is no known confidentiality or integrity impact, and the vulnerability does not enable code execution or privilege escalation. The scope is limited to systems using this specific panel hardware (Feedly).
The Linux kernel maintainers have released fixes across multiple stable branches. Patched versions include Linux 6.6.122, 6.12.67, 6.18.7, and 6.19-rc6, as well as downstream distributions such as Ubuntu (USN-8162-1, USN-8180-1 through USN-8180-6, USN-8186-1, USN-8188-1, USN-8275-1, USN-8278-1, USN-8289-1, USN-8296-1, USN-8297-1) and SUSE (SUSE-2026-0962-1). Users running affected kernel versions on hardware with the DataImage SCF0700C48GGU18 panel should update to a patched kernel version. No configuration-based workaround is available; upgrading is the only remediation (Feedly, Ubuntu USN-8162-1, Ubuntu USN-8180-1).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."