SB2026030458 - Memory leak in Linux kernel video fbdev driver
Published: March 4, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2026-23236)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the ufx_ops_ioctl() function in drivers/video/fbdev/smscufx.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/061cfeb560aa3ddc174153dbe5be9d0b55eb7248
- https://git.kernel.org/stable/c/0634e8d650993602fc5b389ff7ac525f6542e141
- https://git.kernel.org/stable/c/120adae7b42faa641179270c067864544a50ab69
- https://git.kernel.org/stable/c/1c008ad0f0d1c1523902b9cdb08e404129677bfc
- https://git.kernel.org/stable/c/52917e265aa5f848212f60fc50fc504d8ef12866
- https://git.kernel.org/stable/c/6167af934f956d3ae1e06d61f45cd0d1004bbe1a
- https://git.kernel.org/stable/c/a0321e6e58facb39fe191caa0e52ed9aab6a48fe
- https://git.kernel.org/stable/c/f1e91bd4efeae48b0f42caed7e8ce2e3a0d05b02