CVE-2026-72270

UnknownEPSS 0.21%

Last modified

CVE-2026-72270 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: fbdev: s3fb: fix potential memory leak in s3_pci_probe() In s3_pci_probe(), the memory allocated for modelist using fb_videomode_to_modelist() is not freed in subsequent error paths. Fix that by calling fb_destroy_modelist(). EPSS estimates a 0.21% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: fbdev: s3fb: fix potential memory leak in s3_pci_probe() In s3_pci_probe(), the memory allocated for modelist using fb_videomode_to_modelist() is not freed in subsequent error paths. Fix that by calling fb_destroy_modelist()

Metrics

EPSS Probability
0.21%

11.6th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 86c0f043a737dadf034a4e6f29aefb074f4a1146, < 37f4b8bd9e3835a7d4da26baf80b497e478d3123; >= 86c0f043a737dadf034a4e6f29aefb074f4a1146, < ef6c5e4607483259a0daf6584e9e34ef643a655d; >= 86c0f043a737dadf034a4e6f29aefb074f4a1146, < fc90ec978a3cef6f6d8c6074bee538998c7c9837; >= 86c0f043a737dadf034a4e6f29aefb074f4a1146, < 0d0fa8425b29657b3d3e5bb36f50a50e57c8101f; >= 86c0f043a737dadf034a4e6f29aefb074f4a1146, < 25b354f74b028a3f91b12e6b446256965744c477; >= 86c0f043a737dadf034a4e6f29aefb074f4a1146, < ad54698255a4b988cae1ad908c158c1d4128887c; >= 86c0f043a737dadf034a4e6f29aefb074f4a1146, < 56964e8039150a14462005458b25f19d6cad8f4a; >= 86c0f043a737dadf034a4e6f29aefb074f4a1146, < 3b0ed04bc852887a9164e1bbf521652e8ef3eb92
LinuxLinux3.0

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-72270?
In the Linux kernel, the following vulnerability has been resolved: fbdev: s3fb: fix potential memory leak in s3_pci_probe() In s3_pci_probe(), the memory allocated for modelist using fb_videomode_to_modelist() is not freed in subsequent error paths. Fix that by calling fb_destroy_modelist()
How severe is CVE-2026-72270?
Severity scoring for CVE-2026-72270 is pending analysis. The EPSS model estimates a 0.21% probability of exploitation in the next 30 days.
How do I fix CVE-2026-72270?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-72270?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST