Bug 2506826 (CVE-2026-64245) - CVE-2026-64245 kernel: fbdev: modedb: fix a possible UAF in fb_find_mode()
Summary: CVE-2026-64245 kernel: fbdev: modedb: fix a possible UAF in fb_find_mode()
Keywords:
Status: NEW
Alias: CVE-2026-64245
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-24 16:06 UTC by OSIDB Bzimport
Modified: 2026-07-28 12:37 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-24 16:06:41 UTC
In the Linux kernel, the following vulnerability has been resolved:

fbdev: modedb: fix a possible UAF in fb_find_mode()

If mode_option is NULL, it is assigned from mode_option_buf:

  if (!mode_option) {
    fb_get_options(NULL, &mode_option_buf);
    mode_option = mode_option_buf;
  }

Later, name is assigned from mode_option:

  const char *name = mode_option;

However, mode_option_buf is freed before name is no longer used:

  kfree(mode_option_buf);

while name is still accessed by:

  if ((name_matches(db[i], name, namelen) ||

Since name aliases mode_option_buf, this may result in a
use-after-free.

Fix this by extending the lifetime of mode_option_buf until the end of the
function by using scope-based resource management for cleanup.

Comment 1 Mauro Matteo Cascella 2026-07-28 12:36:28 UTC
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026072418-CVE-2026-64245-d57c@gregkh/T


Note You need to log in before you can comment on or make changes to this bug.