CVE-2026-72267
Last modified
CVE-2026-72267 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: fbdev: carminefb: fix potential memory leak in alloc_carmine_fb() The memory allocated for modelist in fb_videomode_to_modelist() is not freed in the subsequent error path. Fix that by calling fb_destroy_modelist(). EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: fbdev: carminefb: fix potential memory leak in alloc_carmine_fb() The memory allocated for modelist in fb_videomode_to_modelist() is not freed in the subsequent error path. Fix that by calling fb_destroy_modelist()
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 2ece5f43b041b96fa2a05107a10a6b0ea0c03a3b, < 97b6c3f6e82a526d95dcfbfcf1c42ba44c61c3d6; >= 2ece5f43b041b96fa2a05107a10a6b0ea0c03a3b, < 6069044e74b7510bf2f034ccd049bc962fb9c765; >= 2ece5f43b041b96fa2a05107a10a6b0ea0c03a3b, < b51990be8411335c263b51e9f4def1e84bfaa923; >= 2ece5f43b041b96fa2a05107a10a6b0ea0c03a3b, < d21e6747f3f68dcce59b5d2205f98633d28f69eb; >= 2ece5f43b041b96fa2a05107a10a6b0ea0c03a3b, < bcc43b2f7410eddb21f73e9a650499a6432c9383; >= 2ece5f43b041b96fa2a05107a10a6b0ea0c03a3b, < d81860691e4cfa14d596136ea2727f244e9e5950; >= 2ece5f43b041b96fa2a05107a10a6b0ea0c03a3b, < dae8f6ddc35cb1673dba32d2fd8f1f85cd377adf; >= 2ece5f43b041b96fa2a05107a10a6b0ea0c03a3b, < 6fcca16a2b19c37f60693c56cbc0c923364ff3ef |
| Linux | Linux | 2.6.27 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-72267?
How severe is CVE-2026-72267?
How do I fix CVE-2026-72267?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-72261In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-72262In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-72263In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72264In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72265In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72266In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72268In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72269In the Linux kernel, the following vulnerability has been re…
- CVE-2026-7227A vulnerability was detected in SourceCodester Pizzafy Ecomm…7.3
- CVE-2026-72270In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72271In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72272In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-72267?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
