Description
In the Linux kernel, the following vulnerability has been resolved:

fbdev: hecubafb: fix potential memory leak in hecubafb_probe()

The memory allocated for pagerefs in fb_deferred_io_init() is not freed
on the error path. Fix it by calling fb_deferred_io_cleanup().
Published: 2026-08-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A memory allocation performed by the Linux kernel framebuffer driver "hecubafb" during the probe phase is not released on error paths, resulting in a kernel‑space memory leak. If the error condition is repeatedly triggered, the kernel will continue to consume page references that are never freed, which can eventually exhaust system memory and bring the system to a halt or force a reboot. This does not provide arbitrary code execution but can be used for local denial of service against privileged users or in a compromised environment. The weakness corresponds to an improper resource handling flaw (CWE-401) and an improper resource release flaw (CWE-772).

Affected Systems

All Linux kernel installations that include the hecubafb framebuffer driver are potentially affected. No specific kernel version range is supplied in the advisory; therefore any kernel build that contains the pre‑fix code paths should be examined and updated once the patch is released. The vendor product is the Linux kernel, maintained by the Linux kernel community.

Risk and Exploitability

The risk of this flaw is moderate with a CVSS score of 5.5. The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation yet. The flaw requires local access to trigger the probe failure and drive the memory leak; thus the attack vector is likely purely local or through a privileged kernel module load. The severity is a denial‑of‑service condition but it is not classified as a direct remote code execution or privilege escalation flaw.

Generated by OpenCVE AI on August 22, 2026 at 07:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the commit introducing fb_deferred_io_cleanup() in the error path of hecubafb_probe()
  • If an immediate kernel upgrade is not possible, rebuild the kernel or the framebuffer module with the patch applied, ensuring that fb_deferred_io_cleanup() is invoked on all error paths to release the allocated page references
  • Monitor system memory usage for signs of abnormal allocation growth and isolate or reconfigure any processes that may trigger repeated error paths in the framebuffer driver

Generated by OpenCVE AI on August 22, 2026 at 07:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Low


Sat, 15 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: fbdev: hecubafb: fix potential memory leak in hecubafb_probe() The memory allocated for pagerefs in fb_deferred_io_init() is not freed on the error path. Fix it by calling fb_deferred_io_cleanup().
Title fbdev: hecubafb: fix potential memory leak in hecubafb_probe()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:11:34.481Z

Reserved: 2026-08-09T03:40:39.916Z

Link: CVE-2026-72274

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:21:57.107

Modified: 2026-08-17T06:18:29.930

Link: CVE-2026-72274

cve-icon Redhat

Severity : Low

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72274 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T07:15:04Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime

  • CWE-772

    Missing Release of Resource after Effective Lifetime