← All Advisories

CVE-2026-97604

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97604

Key Details

CVECVE-2026-97604
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

fbdev: vfb: defer cleanup until the last reference

FBIOGETCMAP takes a shallow snapshot of info->cmap and performs the

usercopy after dropping info->lock. vfb_remove() frees the colormap

immediately after unregistering the framebuffer, even when an open file

still holds a reference to fb_info. A concurrent driver unbind can

therefore free the colormap while the ioctl copies it to userspace.

KASAN reports:

BUG: KASAN: slab-use-after-free in _copy_to_user

Read of size 512 by task poc/125

_copy_to_user (./include/linux/instrumented.h:129 ./include/linux/uaccess.h:201 lib/usercopy.c:24)

fb_cmap_to_user (./include/linux/uaccess.h:230 drivers/video/fbdev/core/fbcmap.c:211)

do_fb_ioctl (drivers/video/fbdev/core/fb_chrdev.c:114)

Allocated by task 1:

fb_alloc_cmap_gfp (./include/linux/slab.h:973 ./include/linux/slab.h:1290 drivers/video/fbdev/core/fbcmap.c:108)

vfb_probe (drivers/video/fbdev/vfb.c:459)

Freed by task 124:

fb_dealloc_cmap (drivers/video/fbdev/core/fbcmap.c:151)

vfb_remove (drivers/video/fbdev/vfb.c:489)

unregister_framebuffer() drops the registration reference, and fbdev calls

fb_destroy after the last put_fb_info(). Move the registered framebuffer's

cleanup into an fb_destroy callback so its colormap and screen buffer stay

alive until all file references have been released. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97604
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97604