CVE-2026-43497

In the Linux kernel, the following vulnerability has been resolved: fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free dlfb_ops_mmap() uses remap_pfn_range() to map vmalloc framebuffer pages to userspace but sets no vm_ops on the VMA. This means the kernel cannot track active mmaps. When dlfb_realloc_framebuffer() replaces the backing buffer via FBIOPUT_VSCREENINFO, existing mmap PTEs are not invalidated. On USB disconnect, dlfb_ops_destroy() calls vfree() on the old pages while userspace PTEs still reference them, resulting in a use-after-free: the process retains read/write access to freed kernel pages. Add vm_operations_struct with open/close callbacks that maintain an atomic mmap_count on struct dlfb_data. In dlfb_realloc_framebuffer(), check mmap_count and return -EBUSY if the buffer is currently mapped, preventing buffer replacement while userspace holds stale PTEs. Tested with PoC using dummy_hcd + raw_gadget USB device emulation.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*

History

23 Jul 2026, 16:10

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: fbdev: udlfb: añadir vm_ops a dlfb_ops_mmap para prevenir el uso después de liberación dlfb_ops_mmap() utiliza remap_pfn_range() para mapear páginas de framebuffer de vmalloc al espacio de usuario, pero no establece vm_ops en el VMA. Esto significa que el kernel no puede rastrear mmaps activos. Cuando dlfb_realloc_framebuffer() reemplaza el búfer de respaldo a través de FBIOPUT_VSCREENINFO, los PTEs de mmap existentes no se invalidan. Al desconectar el USB, dlfb_ops_destroy() llama a vfree() en las páginas antiguas mientras los PTEs del espacio de usuario aún las referencian, lo que resulta en un uso después de liberación: el proceso retiene acceso de lectura/escritura a páginas del kernel liberadas. Añadir vm_operations_struct con callbacks de apertura/cierre que mantienen un mmap_count atómico en la estructura dlfb_data. En dlfb_realloc_framebuffer(), comprobar mmap_count y devolver -EBUSY si el búfer está actualmente mapeado, lo que previene el reemplazo del búfer mientras el espacio de usuario mantiene PTEs obsoletos. Probado con PoC utilizando emulación de dispositivo USB dummy_hcd + raw_gadget.

26 Jun 2026, 17:29

Type Values Removed Values Added
First Time Linux linux Kernel
Linux
CWE CWE-416
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
References () https://git.kernel.org/stable/c/18dd358de72d57993422cbb5dfb29ccd74efe192 - () https://git.kernel.org/stable/c/18dd358de72d57993422cbb5dfb29ccd74efe192 - Patch
References () https://git.kernel.org/stable/c/4f312c30f0368e8d2a76aa650dff73f23490b5e7 - () https://git.kernel.org/stable/c/4f312c30f0368e8d2a76aa650dff73f23490b5e7 - Patch
References () https://git.kernel.org/stable/c/5931f5651ee32bd41b3323256b31fcc8e71336ed - () https://git.kernel.org/stable/c/5931f5651ee32bd41b3323256b31fcc8e71336ed - Patch
References () https://git.kernel.org/stable/c/60f711cfd580f86fea8284146ac133804e728f9a - () https://git.kernel.org/stable/c/60f711cfd580f86fea8284146ac133804e728f9a - Patch
References () https://git.kernel.org/stable/c/8de779dc40d35d39fa07387b6f921eb11df0f511 - () https://git.kernel.org/stable/c/8de779dc40d35d39fa07387b6f921eb11df0f511 - Patch
References () https://git.kernel.org/stable/c/a2c53a3822ee26e8d758071815b9ed3bf6669fc1 - () https://git.kernel.org/stable/c/a2c53a3822ee26e8d758071815b9ed3bf6669fc1 - Patch
References () https://git.kernel.org/stable/c/da9b065cedfd3b574f229d5be594e6aa47a27ae6 - () https://git.kernel.org/stable/c/da9b065cedfd3b574f229d5be594e6aa47a27ae6 - Patch
References () https://git.kernel.org/stable/c/e3d9865dacd7435b8465848428210d0f0c673311 - () https://git.kernel.org/stable/c/e3d9865dacd7435b8465848428210d0f0c673311 - Patch

01 Jun 2026, 17:17

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/5931f5651ee32bd41b3323256b31fcc8e71336ed -
  • () https://git.kernel.org/stable/c/60f711cfd580f86fea8284146ac133804e728f9a -
  • () https://git.kernel.org/stable/c/e3d9865dacd7435b8465848428210d0f0c673311 -

30 May 2026, 11:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.3

21 May 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-21 13:16

Updated : 2026-07-23 16:10


NVD link : CVE-2026-43497

Mitre link : CVE-2026-43497

CVE.ORG link : CVE-2026-43497


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-416

Use After Free