Description
In the Linux kernel, the following vulnerability has been resolved:

fbdev: nvidia: fix potential memory leak in nvidiafb_probe()

In nvidiafb_probe(), the memory allocated for modelist in
nvidia_set_fbinfo() is not freed in the subsequent error paths.
Fix that by calling fb_destroy_modelist().
Published: 2026-08-15
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises in the Linux kernel’s framebuffer driver for NVIDIA graphics hardware. During initialization, the function nvidiafb_probe allocates memory for a modeline list that is never released on error paths. This omission can cause a memory leak, gradually consuming kernel memory. Over time, the leak can exhaust available memory, potentially causing the kernel to OOM-kill processes or become unresponsive, thereby degrading system availability. The flaw is a classic resource exhaustion problem and is classified as a memory leak. No known privilege escalation or remote code execution capability is associated with this issue.

Affected Systems

All installations of the Linux kernel that include the NVIDIA framebuffer driver are impacted. No specific kernel version range is listed in the advisory, so any kernel build incorporating the unpatched code may be vulnerable. Users running modern distributions should verify whether their kernel has incorporated the internal patch to the nvidiafb driver.

Risk and Exploitability

The exploitability of the defect is low because it requires privilege as the code runs in kernel mode and needs to be triggered during device initialization. No public exploits exist, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. The risk is limited to denial of service in environments that load the NVIDIA framebuffer and can exhaust memory if the leak is repeated or compounded. Adversaries would have to gain local access to the system to trigger the bug or rely on a hardware change that forces a reload of the driver.

Generated by OpenCVE AI on August 15, 2026 at 10:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that contains the fix applied in nvidiafb_probe, ensuring that the modeline list is properly destroyed on failure.
  • If upgrading is not immediately possible, restrict the use of the NVIDIA framebuffer driver or remove NVIDIA graphics support from the kernel modules that may load unexpectedly.
  • Configure kernel watchdog timers and memory limits to detect and recover from unintended memory exhaustion, mitigating the impact of the leak if it occurs.
  • Monitor system logs for messages related to framebuffer device initialization failures and memory allocation anomalies.

Generated by OpenCVE AI on August 15, 2026 at 10:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 15 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: fbdev: nvidia: fix potential memory leak in nvidiafb_probe() In nvidiafb_probe(), the memory allocated for modelist in nvidia_set_fbinfo() is not freed in the subsequent error paths. Fix that by calling fb_destroy_modelist().
Title fbdev: nvidia: fix potential memory leak in nvidiafb_probe()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-15T05:54:51.506Z

Reserved: 2026-08-09T03:40:39.915Z

Link: CVE-2026-72265

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:21:54.913

Modified: 2026-08-15T06:21:54.913

Link: CVE-2026-72265

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-15T10:15:03Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime