Use-after-free in Linux kernel - CVE-2026-80785
Published: September 5, 2026
Vulnerability details
The vulnerability allows a local user to store a stale pointer to freed memory in fb_info->mode.
The vulnerability exists due to a use-after-free race condition in the fbdev mode sysfs handlers in drivers/video/fbdev/core/fbsysfs.c when concurrently accessing mode sysfs attributes while the modelist is replaced. A local user can race mode sysfs reads or writes with modelist replacement to store a stale pointer to freed memory in fb_info->mode.