Executive brief
A vulnerability was identified in the Linux kernel's DisplayLink USB framebuffer driver (udlfb). This driver is responsible for managing video output to USB-connected monitors. An issue in how the driver handles memory mapping could allow a local user to maintain access to memory after it has been freed by the system, potentially leading to a system crash or unauthorized access to sensitive data.
Technical details
A use-after-free vulnerability exists in the Linux kernel's udlfb driver within the fbdev subsystem. The dlfb_ops_mmap() function uses remap_pfn_range() to map vmalloc framebuffer pages to userspace but fails to set vm_ops on the Virtual Memory Area (VMA), preventing the kernel from tracking active mmaps. When the backing buffer is replaced via FBIOPUT_VSCREENINFO or during a USB disconnect, the driver calls vfree() on pages that userspace Page Table Entries (PTEs) still reference. A local attacker can exploit this to retain read/write access to freed kernel memory. The fix introduces a vm_operations_struct to track mmap counts and prevents buffer reallocation while active mappings exist.
Affected products
- Linux Linux Kernel udlfb driver
Timeline
- 2026-05-03: other: Patch authored
- 2026-05-21: disclosed: CVE published
References
- https://git.kernel.org/stable/c/18dd358de72d57993422cbb5dfb29ccd74efe192
- https://git.kernel.org/stable/c/4f312c30f0368e8d2a76aa650dff73f23490b5e7
- https://git.kernel.org/stable/c/8de779dc40d35d39fa07387b6f921eb11df0f511
- https://git.kernel.org/stable/c/a2c53a3822ee26e8d758071815b9ed3bf6669fc1
- https://git.kernel.org/stable/c/da9b065cedfd3b574f229d5be594e6aa47a27ae6