PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72267 Linux CVE debrief

The Linux kernel's fbdev carminefb driver has a potential memory leak vulnerability. In the alloc_carmine_fb() function, memory is allocated for modelist using fb_videomode_to_modelist(), but it is not freed in the subsequent error path. This can lead to memory leaks if errors occur during framebuffer allocation. The fix involves adding a call to fb_destroy_modelist() in the error path to ensure proper memory cleanup. Affected systems may be vulnerable to denial-of-service or information disclosure attacks. System administrators should prioritize patching. The vulnerability arises from a missing call to fb_destroy_modelist() in the error path of alloc_carmine_fb(). This could lead to memory leaks if errors occur during framebuffer allocation.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-15
Advisory published
2026-08-15
Advisory updated
2026-08-15

Who should care

System administrators and security teams managing Linux systems that use the carminefb driver should be aware of this vulnerability. This includes organizations using Linux in their infrastructure, especially those with systems that handle graphical output or have exposure to untrusted input.

Technical summary

The Linux kernel's fbdev carminefb driver has a potential memory leak vulnerability. In the alloc_carmine_fb() function, memory is allocated for modelist using fb_videomode_to_modelist(), but it is not freed in the subsequent error path. This can lead to memory leaks if errors occur during framebuffer allocation. The fix involves adding a call to fb_destroy_modelist() in the error path to ensure proper memory cleanup.

Defensive priority

This CVE addresses a potential memory leak in the Linux kernel's fbdev carminefb driver. Affected systems may be vulnerable to denial-of-service or information disclosure attacks. System administrators should prioritize patching.

Recommended defensive actions

  • Inventory and assess Linux systems using the carminefb driver for exposure
  • Apply the kernel patch or update to a version that includes the fix
  • Monitor system logs for signs of potential memory leaks or denial-of-service attempts
  • Consider implementing compensating controls such as memory leak detection tools
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE details a potential memory leak in the Linux kernel's fbdev carminefb driver. The vulnerability arises from a missing call to fb_destroy_modelist() in the error path of alloc_carmine_fb(). This could lead to memory leaks if errors occur during framebuffer allocation. The fix involves adding a call to fb_destroy_modelist() in the error path.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72267 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72267

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72267 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72267

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/6069044e74b7510bf2f034ccd049bc962fb9c765

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/6fcca16a2b19c37f60693c56cbc0c923364ff3ef

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/97b6c3f6e82a526d95dcfbfcf1c42ba44c61c3d6

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b51990be8411335c263b51e9f4def1e84bfaa923

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/bcc43b2f7410eddb21f73e9a650499a6432c9383

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/d21e6747f3f68dcce59b5d2205f98633d28f69eb

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/d81860691e4cfa14d596136ea2727f244e9e5950

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.