CVE-2026-74320

Updated on 15 Aug 2026

Severity

Awaiting Analysis

Details

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved:

fbdev: sm501fb: Fix buffer errors in OF binding code

The code that gets the frame buffer mode from OF has ‘use after free’, ‘buffer overrun’ and memory leaks.

info->edid_data isn’t free if the probe functions fail or if pd->def_mode is set.

If both the CRT and PANEL are enabled info->edid_data is used after being freed and is freed twice.

The string returned by of_get_property(np, “mode”, &len) is just written over either the static “640x480-16@60” or the module parameter string without any regard for the length (which is most likely longer).

Use kstrump() for the OF mode and free everything before freeing ‘info.

Details

Affected packages:
linux @ 5.10.259 (+4 more)

Fixes

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
Oracle Linux 9 UEK 7 Planned