Executive brief
A vulnerability in the Linux kernel's framebuffer driver could lead to system instability or crashes when a graphics device is physically unplugged. If a user application is still accessing the device's memory at the moment it is removed, the system may attempt to use memory that has already been freed. This primarily affects systems where graphics hardware can be hot-swapped or disconnected while in use.
Technical details
A use-after-free vulnerability exists in the Linux kernel's fbdev deferred I/O (defio) implementation. The root cause is that the lifetime of deferred I/O state was incorrectly tied to the 'struct fb_info' object. When a graphics device is hot-unplugged, 'fb_info' is freed; however, if a userspace process still has an active memory mapping of the graphics memory, subsequent access to that mapping will operate on the now-freed 'fb_info' structure. The fix introduces 'struct fb_deferred_io_state' with its own reference counting (kref), ensuring the state persists until the final mapping is closed. If the device is removed, the state is invalidated, causing subsequent accesses to trigger a SIGBUS signal instead of accessing undefined memory.
Affected products
- Linux Linux kernel v2.6.22+
Timeline
- 2026-05-04: patched: Initial patch authored by Thomas Zimmermann
- 2026-05-27: advisory: CVE-2026-46065 published by kernel.org and NVD
References
- https://git.kernel.org/stable/c/25c2b77bc463f29ee71a54b883548baf9386a0db
- https://git.kernel.org/stable/c/2a40f8bc9bb713329f1c35ffc199ee961a7135b0
- https://git.kernel.org/stable/c/2b53d3a52e8e5403a4f4fb57ac6cad3fd2cb1066
- https://git.kernel.org/stable/c/9ded47ad003f09a94b6a710b5c47f4aa5ceb7429
- https://git.kernel.org/stable/c/a0aafb421dd15e935d81543152617f2742cefa70