CVE-2026-97604

In the Linux kernel, the following vulnerability has been resolved: fbdev: vfb: defer cleanup until the last reference FBIOGETCMAP takes a shallow snapshot of info->cmap and performs the usercopy after dropping info->lock. vfb_remove() frees the colormap immediately after unregistering the framebuffer, even when an open file still holds a reference to fb_info. A concurrent driver unbind can therefore free the colormap while the ioctl copies it to userspace. KASAN reports: BUG: KASAN: slab-use-after-free in _copy_to_user Read of size 512 by task poc/125 _copy_to_user (./include/linux/instrumented.h:129 ./include/linux/uaccess.h:201 lib/usercopy.c:24) fb_cmap_to_user (./include/linux/uaccess.h:230 drivers/video/fbdev/core/fbcmap.c:211) do_fb_ioctl (drivers/video/fbdev/core/fb_chrdev.c:114) Allocated by task 1: fb_alloc_cmap_gfp (./include/linux/slab.h:973 ./include/linux/slab.h:1290 drivers/video/fbdev/core/fbcmap.c:108) vfb_probe (drivers/video/fbdev/vfb.c:459) Freed by task 124: fb_dealloc_cmap (drivers/video/fbdev/core/fbcmap.c:151) vfb_remove (drivers/video/fbdev/vfb.c:489) unregister_framebuffer() drops the registration reference, and fbdev calls fb_destroy after the last put_fb_info(). Move the registered framebuffer's cleanup into an fb_destroy callback so its colormap and screen buffer stay alive until all file references have been released.

Package Linux Kernel
Published 2026-09-25
Last modified 2026-10-03
Patch available
Yes

Affected versions

Linux kernel versions 2.6.30 and later are affected. Fixed in 5.10.271, 5.15.222, 6.1.189, 6.6.158, 6.12.111, 6.18.53, 7.2.7, 7.3-rc3 and their respective stable series.

Affected from
≥ 2.6.30
Fixed in
✓ 5.10.271 5.10.x ✓ 5.15.222 5.15.x ✓ 6.1.189 6.1.x ✓ 6.6.158 6.6.x ✓ 6.12.111 6.12.x ✓ 6.18.53 6.18.x ✓ 7.2.7 7.2.x ✓ 7.3-rc3

Frequently asked questions

  • What is CVE-2026-97604?

    CVE-2026-97604 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 2.6.30 onward and has been patched in 5.10.271, 5.15.222, 6.1.189 and others. CVE-2026-97604 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-97604?

    Yes. CVE-2026-97604 has been patched. Fixed versions include 5.10.271, 5.15.222, 6.1.189 and others. If you are running Linux kernel 2.6.30 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-97604 actively exploited?

    No. CVE-2026-97604 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.