Junglewise Threat Intelligence

CVE-2026-53401: Linux Kernel use-after-free in omapfb_mmap

CVE-2026-53401 · Severity: info · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's OMAP2 display driver that could allow a local attacker to access memory after it has been freed. This component is responsible for managing framebuffers on certain hardware platforms. An exploit could lead to system instability, unauthorized access to sensitive data in memory, or potentially a full system compromise.

Technical details

A use-after-free vulnerability exists in drivers/video/fbdev/omap2/omapfb/omapfb-main.c due to a race condition between omapfb_mmap() and OMAPFB_SETUP_PLANE ioctl handlers. The omapfb_mmap() function holds mm_lock but fails to hold fb_info->lock, while the ioctl handlers hold fb_info->lock but not mm_lock. This allows a concurrent execution where omapfb_mmap() retrieves an old memory region reference but maps physical addresses from a newly assigned region, while the new region's reference count is not properly incremented. Consequently, the new region can be freed while userspace still maintains a mapping to it. The issue is resolved by ensuring all required values are read from the same region reference that is being reference-counted. Patched in Linux kernel version 7.1.3.

Affected products

  • Linux Linux Kernel versions before 7.1.3

Timeline

  • 2026-06-02: other: Fix authored
  • 2026-07-19: disclosed: CVE published
  • 2026-07-19: advisory

References

Related threats