CVE-2026-64245

Source
https://cve.org/CVERecord?id=CVE-2026-64245
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64245.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64245
Downstream
Published
2026-07-24T15:31:14.142Z
Modified
2026-07-28T04:03:02.489409009Z
Summary
fbdev: modedb: fix a possible UAF in fb_find_mode()
Details

In the Linux kernel, the following vulnerability has been resolved:

fbdev: modedb: fix a possible UAF in fbfindmode()

If modeoption is NULL, it is assigned from modeoption_buf:

if (!modeoption) { fbgetoptions(NULL, &modeoptionbuf); modeoption = modeoptionbuf; }

Later, name is assigned from mode_option:

const char *name = mode_option;

However, modeoptionbuf is freed before name is no longer used:

kfree(modeoptionbuf);

while name is still accessed by:

if ((name_matches(db[i], name, namelen) ||

Since name aliases modeoptionbuf, this may result in a use-after-free.

Fix this by extending the lifetime of modeoptionbuf until the end of the function by using scope-based resource management for cleanup.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64245.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
089d924d03d5c17b05d02992f57671ccfba1c4f0
Fixed
c7dc382439f7b019e207055b52e9cec051d42fa9
Fixed
f906347d75c7fc377041c6d3c535d0f08846aada
Fixed
4d418cf8daf57e454b4d855bf9b2419fd8e6a540
Fixed
13b6f0cdd5cd5e60f682ec43134ab0e2024bd356
Fixed
85b6256469cebdac395e7447147e06b2e151014f

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64245.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.4.0
Fixed
6.6.144
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.95
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.38
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64245.json"