๐Ÿ” CVE Alert

CVE-2026-97604

UNKNOWN 0.0

fbdev: vfb: defer cleanup until the last reference

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: fbdev: vfb: defer cleanup until the last reference FBIOGETCMAP takes a shallow snapshot of info->cmap and performs the usercopy after dropping info->lock. vfb_remove() frees the colormap immediately after unregistering the framebuffer, even when an open file still holds a reference to fb_info. A concurrent driver unbind can therefore free the colormap while the ioctl copies it to userspace. KASAN reports: BUG: KASAN: slab-use-after-free in _copy_to_user Read of size 512 by task poc/125 _copy_to_user (./include/linux/instrumented.h:129 ./include/linux/uaccess.h:201 lib/usercopy.c:24) fb_cmap_to_user (./include/linux/uaccess.h:230 drivers/video/fbdev/core/fbcmap.c:211) do_fb_ioctl (drivers/video/fbdev/core/fb_chrdev.c:114) Allocated by task 1: fb_alloc_cmap_gfp (./include/linux/slab.h:973 ./include/linux/slab.h:1290 drivers/video/fbdev/core/fbcmap.c:108) vfb_probe (drivers/video/fbdev/vfb.c:459) Freed by task 124: fb_dealloc_cmap (drivers/video/fbdev/core/fbcmap.c:151) vfb_remove (drivers/video/fbdev/vfb.c:489) unregister_framebuffer() drops the registration reference, and fbdev calls fb_destroy after the last put_fb_info(). Move the registered framebuffer's cleanup into an fb_destroy callback so its colormap and screen buffer stay alive until all file references have been released.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
5e266e2e0e19532c1b8e2e2bff1eb6ccf42e478a < 86356f13598f59f5acb1754895747dcdaf65a254 5e266e2e0e19532c1b8e2e2bff1eb6ccf42e478a < 5ff1effb047e465cde193d7df95988aa1520035e 5e266e2e0e19532c1b8e2e2bff1eb6ccf42e478a < 3c91e51a53cf805e551e5dc8149cd0539a6dbb9d 5e266e2e0e19532c1b8e2e2bff1eb6ccf42e478a < a0a34a40ed299c9c7cff6af163a5b883ee9d6d73
Linux / Linux
2.6.30

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/86356f13598f59f5acb1754895747dcdaf65a254 git.kernel.org: https://git.kernel.org/stable/c/5ff1effb047e465cde193d7df95988aa1520035e git.kernel.org: https://git.kernel.org/stable/c/3c91e51a53cf805e551e5dc8149cd0539a6dbb9d git.kernel.org: https://git.kernel.org/stable/c/a0a34a40ed299c9c7cff6af163a5b883ee9d6d73