SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-64245

HIGH · CVSS 7.8 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

The vulnerability in the Linux kernel's framebuffer device (fbdev) arises from a use-after-free condition due to improper management of memory associated with mode_option_buf. This flaw could potentially allow an attacker to exploit the freed memory, leading to undefined behavior or system crashes. Organizations using affected Linux kernel versions should prioritize patching this vulnerability to mitigate risks associated with memory corruption and potential system instability.

CVE
CVE-2026-64245
Severity
HIGH
CVSS
7.8
EPSS
0.12%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: fbdev: modedb: fix a possible UAF in fb_find_mode() If mode_option is NULL, it is assigned from mode_option_buf: if (!mode_option) { fb_get_options(NULL, &mode_option_buf); mode_option = mode_option_buf; } Later, name is assigned from mode_option: const char *name = mode_option; However, mode_option_buf is freed before name is no longer used: kfree(mode_option_buf); while name is still accessed by: if ((name_matches(db[i], name, namelen) || Since name aliases mode_option_buf, this may result in a use-after-free. Fix this by extending the lifetime of mode_option_buf until the end of the function by using scope-based resource management for cleanup.

Related CVEs

Other vulnerabilities affecting the same vendor(s)