In the Linux kernel, the following vulnerability has been resolved: drm/vrr: Set VRR capable prop only if it is attached to connector VRR capable property is not attached by default to the connector It is attached only if VRR is supported. So if the driver tries to call drm core set prop function without it being attached that causes NULL dereference.
https://git.kernel.org/stable/c/941e8bcd2b2ba95490738e33dfeca27168452779
https://git.kernel.org/stable/c/85271e92ae4f13aa679acaa6cf76b3c36bcb7bab
https://git.kernel.org/stable/c/62929726ef0ec72cbbe9440c5d125d4278b99894
https://git.kernel.org/stable/c/3534c5c005ef99a1804ed50b8a72cdae254cabb5
https://git.kernel.org/stable/c/0ba557d330946c23559aaea2d51ea649fdeca98a