Description
In the Linux kernel, the following vulnerability has been resolved:

fbdev: i740fb: fix potential memory leak in i740fb_probe()

In i740fb_probe(), the memory allocated in fb_videomode_to_modelist()
for modelist is not freed in the error paths. Fix that by calling
fb_destroy_modelist().
Published: 2026-08-15
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The reported issue is a memory leak in the i740fb framebuffer driver within the Linux kernel. During the probe phase, a memory block allocated for the modelist structure is not freed on error paths, leading to unreleased kernel memory. Repeated or continuous exploitation could deplete kernel address space, causing system instability or crashes. The vulnerability is classified as worth a CWE-401 (Improper Release of Memory).

Affected Systems

All Linux kernel releases that contain the i740fb framebuffer driver and have not yet incorporated the public fix commit. The specific kernel versions are not enumerated in the advisory, but any kernel entry that includes i740fb before the commit date is potentially affected.

Risk and Exploitability

The EPSS score is unavailable and the vulnerability is not listed in CISA KEV, indicating no confirmed widespread exploitation. Because the flaw resides in a low‑level driver that only reacts during hardware initialization, the attack vector is limited to systems with an i740fb device present or accessible through device emulation, and would likely require physical or privileged access to trigger repeated probes. Consequently, the risk is moderate; while exploitation could lead to a denial of service, it is not currently observed or documented.

Generated by OpenCVE AI on August 15, 2026 at 09:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release that includes the i740fb memory‑release fix or apply the bandit commit patches directly.
  • If an immediate kernel upgrade is not possible, disable the i740fb framebuffer driver by blacklisting it in modprobe configuration or removing the associated device to prevent the probe from executing.
  • Continuously monitor system memory usage for anomalous increases that could indicate the residual leak persists, and ensure that any temporary disabling measure is reversed once a permanent kernel update can be applied.

Generated by OpenCVE AI on August 15, 2026 at 09:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 15 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: fbdev: i740fb: fix potential memory leak in i740fb_probe() In i740fb_probe(), the memory allocated in fb_videomode_to_modelist() for modelist is not freed in the error paths. Fix that by calling fb_destroy_modelist().
Title fbdev: i740fb: fix potential memory leak in i740fb_probe()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-15T05:54:55.203Z

Reserved: 2026-08-09T03:40:39.916Z

Link: CVE-2026-72271

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:21:56.093

Modified: 2026-08-15T06:21:56.093

Link: CVE-2026-72271

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-15T10:00:06Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime