In the Linux kernel, the following vulnerability has been resolved: fbdev: vfb: defer cleanup...
🔗 CVE IDs covered (1)
📋 Description
In the Linux kernel, the following vulnerability has been resolved:
fbdev: vfb: defer cleanup until the last reference
FBIOGETCMAP takes a shallow snapshot of info->cmap and performs the usercopy after dropping info->lock. vfb_remove() frees the colormap immediately after unregistering the framebuffer, even when an open file still holds a reference to fb_info. A concurrent driver unbind can therefore free the colormap while the ioctl copies it to userspace.
KASAN reports:
BUG: KASAN: slab-use-after-free in _copy_to_user Read of size 512 by task poc/125
_copy_to_user (./include/linux/instrumented.h:129 ./include/linux/uaccess.h:201 lib/usercopy.c:24) fb_cmap_to_user (./include/linux/uaccess.h:230 drivers/video/fbdev/core/fbcmap.c:211) do_fb_ioctl (drivers/video/fbdev/core/fb_chrdev.c:114)
Allocated by task 1: fb_alloc_cmap_gfp (./include/linux/slab.h:973 ./include/linux/slab.h:1290 drivers/video/fbdev/core/fbcmap.c:108) vfb_probe (drivers/video/fbdev/vfb.c:459)
Freed by task 124: fb_dealloc_cmap (drivers/video/fbdev/core/fbcmap.c:151) vfb_remove (drivers/video/fbdev/vfb.c:489)
unregister_framebuffer() drops the registration reference, and fbdev calls fb_destroy after the last put_fb_info(). Move the registered framebuffer's cleanup into an fb_destroy callback so its colormap and screen buffer stay alive until all file references have been released.
🔗 References (10)
- https://nvd.nist.gov/vuln/detail/CVE-2026-97604
- https://git.kernel.org/stable/c/3c91e51a53cf805e551e5dc8149cd0539a6dbb9d
- https://git.kernel.org/stable/c/5ff1effb047e465cde193d7df95988aa1520035e
- https://git.kernel.org/stable/c/86356f13598f59f5acb1754895747dcdaf65a254
- https://git.kernel.org/stable/c/a0a34a40ed299c9c7cff6af163a5b883ee9d6d73
- https://git.kernel.org/stable/c/040ce3950f64a11e9ee5646c8aaa91fd2e29e245
- https://git.kernel.org/stable/c/ab664e279eb2a68e55895dd115a9488807280f07
- https://git.kernel.org/stable/c/bf49eac7ed11aabd0b9b790c062742a8e4be97c6
- https://git.kernel.org/stable/c/de5a0eda59fe4b3eacd1a67c992e54766bb6683f
- https://github.com/advisories/GHSA-8fh7-qq2h-xhh6