Descripción
In the Linux kernel, the following vulnerability has been resolved: fbdev: sm501fb: Fix buffer errors in OF binding code The code that gets the frame buffer mode from OF has -use after free-, -buffer overrun- and memory leaks. info->edid_data isn-t free if the probe functions fail or if pd->def_mode is set. If both the CRT and PANEL are enabled info->edid_data is used after being freed and is freed twice. The string returned by of_get_property(np, -mode-, &len) is just written over either the static -640x480-16@60- or the module parameter string without any regard for the length (which is most likely longer). Use kstrump() for the OF mode and free everything before freeing -info.
EPSS 0.17700000000000002%Riesgo 0
Ver fuente- Publicación
- 2026-08-15 06:22:32
- Versiones afectadas
- unknown
- Tipo
- Kernel
- Última modificación
- 2026-08-17 06:19:26
- Vector
- Pending