Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-97604— fbdev: vfb: defer cleanup until the last reference

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: fbdev: vfb: 推迟清理操作,直到最后一个引用释放 命令会截取 的浅层副本,并在释放 锁之后执行用户空间拷贝。然而, 在注销帧缓冲设备后立即释放颜色映射(colormap),即使此时仍有打开的文件描述符持有对 的引用。因此,当并发执行的驱动程序解除绑定时,可能在 将颜色映射拷贝到用户空间的过程中,颜色映射已被释放,从而导致使用-after-free 错误。 KASAN(内核地址 sanitizer)报告如下: 会注销注册引用,而 fbdev 子系统会在最后一个 调用

AI Predicted 7.8 Difficulty: Moderate EPSS 0.21% · P10

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 5e266e2e0e19532c1b8e2e2bff1eb6ccf42e478a< bf49eac7ed11aabd0b9b790c062742a8e4be97c6 affected
5e266e2e0e19532c1b8e2e2bff1eb6ccf42e478a< 040ce3950f64a11e9ee5646c8aaa91fd2e29e245 affected
5e266e2e0e19532c1b8e2e2bff1eb6ccf42e478a< ab664e279eb2a68e55895dd115a9488807280f07 affected
5e266e2e0e19532c1b8e2e2bff1eb6ccf42e478a< de5a0eda59fe4b3eacd1a67c992e54766bb6683f affected
5e266e2e0e19532c1b8e2e2bff1eb6ccf42e478a< 86356f13598f59f5acb1754895747dcdaf65a254 affected
5e266e2e0e19532c1b8e2e2bff1eb6ccf42e478a< 5ff1effb047e465cde193d7df95988aa1520035e affected
5e266e2e0e19532c1b8e2e2bff1eb6ccf42e478a< 3c91e51a53cf805e551e5dc8149cd0539a6dbb9d affected
5e266e2e0e19532c1b8e2e2bff1eb6ccf42e478a< a0a34a40ed299c9c7cff6af163a5b883ee9d6d73 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-97604

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
fbdev: vfb: defer cleanup until the last reference
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: fbdev: vfb: defer cleanup until the last reference FBIOGETCMAP takes a shallow snapshot of info->cmap and performs the usercopy after dropping info->lock. vfb_remove() frees the colormap immediately after unregistering the framebuffer, even when an open file still holds a reference to fb_info. A concurrent driver unbind can therefore free the colormap while the ioctl copies it to userspace. KASAN reports: BUG: KASAN: slab-use-after-free in _copy_to_user Read of size 512 by task poc/125 _copy_to_user (./include/linux/instrumented.h:129 ./include/linux/uaccess.h:201 lib/usercopy.c:24) fb_cmap_to_user (./include/linux/uaccess.h:230 drivers/video/fbdev/core/fbcmap.c:211) do_fb_ioctl (drivers/video/fbdev/core/fb_chrdev.c:114) Allocated by task 1: fb_alloc_cmap_gfp (./include/linux/slab.h:973 ./include/linux/slab.h:1290 drivers/video/fbdev/core/fbcmap.c:108) vfb_probe (drivers/video/fbdev/vfb.c:459) Freed by task 124: fb_dealloc_cmap (drivers/video/fbdev/core/fbcmap.c:151) vfb_remove (drivers/video/fbdev/vfb.c:489) unregister_framebuffer() drops the registration reference, and fbdev calls fb_destroy after the last put_fb_info(). Move the registered framebuffer's cleanup into an fb_destroy callback so its colormap and screen buffer stay alive until all file references have been released.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 5e266e2e0e19532c1b8e2e2bff1eb6ccf42e478a ~ bf49eac7ed11aabd0b9b790c062742a8e4be97c6 -
Linux Linux 2.6.30 -

II. Public POCs for CVE-2026-97604

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-97604

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-97604 (8)

Same Patch Batch · Linux · 2026-09-25 · 372 CVEs total

CVE-2026-100075 9.8 CRITICAL RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters
CVE-2026-97957 8.8 HIGH net: hinic: fix mailbox segment buffer overflow
CVE-2026-97527 8.8 HIGH scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock
CVE-2026-97528 8.8 HIGH scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error
CVE-2026-97555 8.8 HIGH smb: client: fix heap overflow in DACL owner/group rewrite
CVE-2026-98115 8.8 HIGH ksmbd: safely drain sessions during logoff
CVE-2026-97525 8.2 HIGH x86/mm/pat: Allocate split page tables as kernel page tables
CVE-2026-97573 8.1 HIGH bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset()
CVE-2026-97570 8.1 HIGH bnxt_en: Bound SW TPA IDs to prevent crashes
CVE-2026-98070 8.1 HIGH net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks()
CVE-2026-98069 8.1 HIGH net/rds: acquire the fastpath locks in rds_conn_shutdown()
CVE-2026-98130 8.1 HIGH sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START
CVE-2026-98116 7.8 HIGH ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF
CVE-2026-97903 7.8 HIGH exit: hold a reference to thread_pid across proc_flush_pid
CVE-2026-97548 7.8 HIGH xfs: fix the rtrmap and rtrefcount _maxlevels_ondisk functions
CVE-2026-97611 7.8 HIGH net: openvswitch: fix use-after-free of the flow table mask array
CVE-2026-97612 7.8 HIGH net: mpls: clear inner_protocol when the last label is popped
CVE-2026-98073 7.8 HIGH net: Remove conflicting altnames for dying netns in __dev_change_net_namespace().
CVE-2026-97602 7.8 HIGH inet: frags: invalidate queues before flushing them
CVE-2026-97577 7.8 HIGH media: verisilicon: rockchip: reject AV1 frames exceeding the tile capacity

Showing top 20 of 372 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-97604

No comments yet


Leave a comment