Junglewise Threat Intelligence

CVE-2026-63826: Linux Kernel use-after-free in fbdev store_modes

CVE-2026-63826 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was discovered in the Linux kernel's framebuffer device (fbdev) subsystem, which manages how graphics are displayed on a screen. Under certain conditions, such as when unbinding a console or changing display modes, the system might try to access memory that has already been freed. This could lead to system instability, crashes, or potentially allow a local user to gain unauthorized access to sensitive information.

Technical details

A use-after-free vulnerability exists in the fbdev subsystem within 'drivers/video/fbdev/core/fbsysfs.c'. The 'store_modes()' function replaces a framebuffer's modelist but fails to update 'fb_display[i].mode' for unmapped consoles and 'fb_info->mode'. These pointers remain stale, pointing to the old modelist that is freed via 'fb_destroy_modelist()'. A local attacker can trigger a use-after-free by reading the 'mode' sysfs attribute (invoking 'show_mode()') or by performing an 'FBIOPUT_VSCREENINFO' ioctl with 'FB_ACTIVATE_INV_MODE'. The fix involves clearing these pointers using 'fbcon_delete_modelist()' before the list is destroyed.

Affected products

  • Linux Linux Kernel 6.6.144, 6.12.95, and others via git commits

Timeline

  • 2026-06-25: other: Vulnerability fixed in source code by Ian Bridges
  • 2026-07-19: disclosed: CVE published

References

Related threats