Junglewise Threat Intelligence

CVE-2026-64245: Linux Kernel use-after-free in fb_find_mode

CVE-2026-64245 · Severity: info · Published 2026-07-24

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's framebuffer device (fbdev) subsystem, which manages how video hardware displays graphics. A technical error in memory management could allow the system to attempt to access data that has already been deleted. In practice, this could lead to system instability, crashes, or potentially allow an attacker to gain unauthorized access to system memory.

Technical details

A use-after-free (UAF) vulnerability exists in drivers/video/fbdev/core/modedb.c within the fb_find_mode() function. When the 'mode_option' parameter is NULL, the function allocates memory to 'mode_option_buf' via fb_get_options(). However, the code explicitly calls kfree(mode_option_buf) while a pointer ('name') aliasing that buffer is still being accessed in subsequent logic, such as name_matches() calls. This flaw can be triggered during video mode detection. The fix implements scope-based resource management (__free(kfree)) to ensure the buffer is only released when the function returns. Patches are available in various stable kernel branches including 6.6.144, 6.12.95, 6.18.38, and 7.1.3.

Affected products

  • Linux Linux 6.5 to 6.6.143, 6.12.94, 6.18.37, 7.1.2

Timeline

  • 2026-06-10: disclosed: Initial patch submitted by Tuo Li
  • 2026-07-24: advisory: CVE-2026-64245 published

References