Executive brief
A vulnerability was discovered in the Linux kernel's framebuffer device (fbdev) subsystem, which manages how graphics are displayed on a screen. Under certain conditions, such as when unbinding a console or changing display modes, the system might try to access memory that has already been freed. This could lead to system instability, crashes, or potentially allow a local user to gain unauthorized access to sensitive information.
Technical details
A use-after-free vulnerability exists in the fbdev subsystem within 'drivers/video/fbdev/core/fbsysfs.c'. The 'store_modes()' function replaces a framebuffer's modelist but fails to update 'fb_display[i].mode' for unmapped consoles and 'fb_info->mode'. These pointers remain stale, pointing to the old modelist that is freed via 'fb_destroy_modelist()'. A local attacker can trigger a use-after-free by reading the 'mode' sysfs attribute (invoking 'show_mode()') or by performing an 'FBIOPUT_VSCREENINFO' ioctl with 'FB_ACTIVATE_INV_MODE'. The fix involves clearing these pointers using 'fbcon_delete_modelist()' before the list is destroyed.
Affected products
- Linux Linux Kernel 6.6.144, 6.12.95, and others via git commits
Timeline
- 2026-06-25: other: Vulnerability fixed in source code by Ian Bridges
- 2026-07-19: disclosed: CVE published
References
- https://git.kernel.org/stable/c/0d35f9f194a858567a21017d69318a51e3a822b9
- https://git.kernel.org/stable/c/2c1c805c65fb7dc7524e20376d6987721e73a0b1
- https://git.kernel.org/stable/c/5267eab88fa4c684459504b8be577ad64953b9a6
- https://git.kernel.org/stable/c/70f1e000b88cfa8ca3fd7f4d082647fc089a7769
- https://git.kernel.org/stable/c/c6765f39ed27014ff877b00a2efa494233404e17