CVE-2026-97604 PUBLISHED

fbdev: vfb: defer cleanup until the last reference

Assigner: Linux
Reserved: 24.09.2026 Published: 25.09.2026 Updated: 25.09.2026

In the Linux kernel, the following vulnerability has been resolved:

fbdev: vfb: defer cleanup until the last reference

FBIOGETCMAP takes a shallow snapshot of info->cmap and performs the usercopy after dropping info->lock. vfb_remove() frees the colormap immediately after unregistering the framebuffer, even when an open file still holds a reference to fb_info. A concurrent driver unbind can therefore free the colormap while the ioctl copies it to userspace.

KASAN reports:

BUG: KASAN: slab-use-after-free in _copy_to_user Read of size 512 by task poc/125

_copy_to_user (./include/linux/instrumented.h:129 ./include/linux/uaccess.h:201 lib/usercopy.c:24) fb_cmap_to_user (./include/linux/uaccess.h:230 drivers/video/fbdev/core/fbcmap.c:211) do_fb_ioctl (drivers/video/fbdev/core/fb_chrdev.c:114)

Allocated by task 1: fb_alloc_cmap_gfp (./include/linux/slab.h:973 ./include/linux/slab.h:1290 drivers/video/fbdev/core/fbcmap.c:108) vfb_probe (drivers/video/fbdev/vfb.c:459)

Freed by task 124: fb_dealloc_cmap (drivers/video/fbdev/core/fbcmap.c:151) vfb_remove (drivers/video/fbdev/vfb.c:489)

unregister_framebuffer() drops the registration reference, and fbdev calls fb_destroy after the last put_fb_info(). Move the registered framebuffer's cleanup into an fb_destroy callback so its colormap and screen buffer stay alive until all file references have been released.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 5e266e2e0e19532c1b8e2e2bff1eb6ccf42e478a to 86356f13598f59f5acb1754895747dcdaf65a254 (excl.)
  • affected from 5e266e2e0e19532c1b8e2e2bff1eb6ccf42e478a to 5ff1effb047e465cde193d7df95988aa1520035e (excl.)
  • affected from 5e266e2e0e19532c1b8e2e2bff1eb6ccf42e478a to 3c91e51a53cf805e551e5dc8149cd0539a6dbb9d (excl.)
  • affected from 5e266e2e0e19532c1b8e2e2bff1eb6ccf42e478a to a0a34a40ed299c9c7cff6af163a5b883ee9d6d73 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 2.6.30 is affected
  • unaffected from 0 to 2.6.30 (excl.)
  • unaffected from 6.12.111 to 6.12.* (incl.)
  • unaffected from 6.18.53 to 6.18.* (incl.)
  • unaffected from 7.2.7 to 7.2.* (incl.)
  • unaffected from 7.3-rc3 to * (incl.)

References