CVE-2026-72267

UnknownEPSS 0.21%

Last modified

CVE-2026-72267 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: fbdev: carminefb: fix potential memory leak in alloc_carmine_fb() The memory allocated for modelist in fb_videomode_to_modelist() is not freed in the subsequent error path. Fix that by calling fb_destroy_modelist(). EPSS estimates a 0.21% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: fbdev: carminefb: fix potential memory leak in alloc_carmine_fb() The memory allocated for modelist in fb_videomode_to_modelist() is not freed in the subsequent error path. Fix that by calling fb_destroy_modelist()

Metrics

EPSS Probability
0.21%

11.6th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 2ece5f43b041b96fa2a05107a10a6b0ea0c03a3b, < 97b6c3f6e82a526d95dcfbfcf1c42ba44c61c3d6; >= 2ece5f43b041b96fa2a05107a10a6b0ea0c03a3b, < 6069044e74b7510bf2f034ccd049bc962fb9c765; >= 2ece5f43b041b96fa2a05107a10a6b0ea0c03a3b, < b51990be8411335c263b51e9f4def1e84bfaa923; >= 2ece5f43b041b96fa2a05107a10a6b0ea0c03a3b, < d21e6747f3f68dcce59b5d2205f98633d28f69eb; >= 2ece5f43b041b96fa2a05107a10a6b0ea0c03a3b, < bcc43b2f7410eddb21f73e9a650499a6432c9383; >= 2ece5f43b041b96fa2a05107a10a6b0ea0c03a3b, < d81860691e4cfa14d596136ea2727f244e9e5950; >= 2ece5f43b041b96fa2a05107a10a6b0ea0c03a3b, < dae8f6ddc35cb1673dba32d2fd8f1f85cd377adf; >= 2ece5f43b041b96fa2a05107a10a6b0ea0c03a3b, < 6fcca16a2b19c37f60693c56cbc0c923364ff3ef
LinuxLinux2.6.27

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-72267?
In the Linux kernel, the following vulnerability has been resolved: fbdev: carminefb: fix potential memory leak in alloc_carmine_fb() The memory allocated for modelist in fb_videomode_to_modelist() is not freed in the subsequent error path. Fix that by calling fb_destroy_modelist()
How severe is CVE-2026-72267?
Severity scoring for CVE-2026-72267 is pending analysis. The EPSS model estimates a 0.21% probability of exploitation in the next 30 days.
How do I fix CVE-2026-72267?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-72267?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST