Junglewise Threat Intelligence

CVE-2026-43497: Linux Kernel udlfb use-after-free in dlfb_ops_mmap

CVE-2026-43497 · Severity: info · CVSS 0 · Published 2026-05-21

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's DisplayLink USB framebuffer driver (udlfb). This driver is responsible for managing video output to USB-connected monitors. An issue in how the driver handles memory mapping could allow a local user to maintain access to memory after it has been freed by the system, potentially leading to a system crash or unauthorized access to sensitive data.

Technical details

A use-after-free vulnerability exists in the Linux kernel's udlfb driver within the fbdev subsystem. The dlfb_ops_mmap() function uses remap_pfn_range() to map vmalloc framebuffer pages to userspace but fails to set vm_ops on the Virtual Memory Area (VMA), preventing the kernel from tracking active mmaps. When the backing buffer is replaced via FBIOPUT_VSCREENINFO or during a USB disconnect, the driver calls vfree() on pages that userspace Page Table Entries (PTEs) still reference. A local attacker can exploit this to retain read/write access to freed kernel memory. The fix introduces a vm_operations_struct to track mmap counts and prevents buffer reallocation while active mappings exist.

Affected products

  • Linux Linux Kernel udlfb driver

Timeline

  • 2026-05-03: other: Patch authored
  • 2026-05-21: disclosed: CVE published

References