{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89597","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.731Z","datePublished":"2026-09-11T19:44:59.538Z","dateUpdated":"2026-09-14T12:01:20.325Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:01:20.325Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: uvesafb: unregister connector callback on init failure\n\nuvesafb_init() registers the v86d connector callback before registering\nthe platform driver. If platform_driver_register() fails, the function\nreturns the error directly and leaves the connector callback registered.\n\nThe later platform-device failure path already unregisters the callback.\nAdd the same cleanup before the final return when platform-driver\nregistration fails.\n\nThis issue was identified during our ongoing static-analysis research while\nreviewing kernel code."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The leftover v86d connector callback is reached only via a local NETLINK_CONNECTOR socket: cn_rx_skb() -> cn_call_callback() invokes the registered handler. There is no remote packet, Bluetooth/WiFi, or USB path into this code.\nAC:L - Once platform_driver_register() fails, cn_add_callback() has already left uvesafb_cn_callback on the global connector list while free_module() unmaps the driver. A single NETLINK_CONNECTOR message with CN_IDX_V86D/CN_VAL_V86D_UVESAFB then calls that stale pointer with no race or other condition beyond the attacker's control.\nPR:L - Unprivileged users may create NETLINK_CONNECTOR sockets and send to kernel portid 0 without CAP_NET_ADMIN. The callback's capable(CAP_SYS_ADMIN) check never runs because the UAF occurs at the call through the freed module text, so init-namespace root is not required.\nUI:N - The attacker sends the netlink message from their own process. No separate victim action such as mounting a filesystem, opening a device node, or loading a module is required to hit the dangling callback.\nS:U - The stale function pointer and freed uvesafb module memory are kernel-side resources in the same security authority. This is local privilege escalation, not VM escape, IOMMU bypass, or another cross-boundary impact.\nC:H - The leftover cn_callback_entry still points at uvesafb_cn_callback in freed module text. That use-after-free lets an attacker reclaim the pages and obtain an arbitrary kernel read primitive.\nI:H - Calling through a function pointer that resides in freed module memory is a control-flow hijack once those pages are reallocated, giving an arbitrary write and code-execution primitive.\nA:H - Invoking the stale connector callback jumps into unmapped or reused module text and reliably oopses or panics the kernel even if the attacker does not fully exploit the UAF."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/video/fbdev/uvesafb.c"],"versions":[{"version":"8bdb3a2d7df48b861972c4bfb58490853a228f51","lessThan":"b149f77d04082a9da75944cdc488becb0e35258f","status":"affected","versionType":"git"},{"version":"8bdb3a2d7df48b861972c4bfb58490853a228f51","lessThan":"0352fdac3cbf11e3b323322ff8cd95e20cbf5cd7","status":"affected","versionType":"git"},{"version":"8bdb3a2d7df48b861972c4bfb58490853a228f51","lessThan":"17518e7123f7ef01b1155064dc01f2087583908e","status":"affected","versionType":"git"},{"version":"8bdb3a2d7df48b861972c4bfb58490853a228f51","lessThan":"9eb7b3cbe99c9c0edbff69eb155c723e30983c22","status":"affected","versionType":"git"},{"version":"8bdb3a2d7df48b861972c4bfb58490853a228f51","lessThan":"9f8a822b44c42502f105cf6574f4867067eecdd0","status":"affected","versionType":"git"},{"version":"8bdb3a2d7df48b861972c4bfb58490853a228f51","lessThan":"466a8af0dee2cf745307155e26884e19a37b7e15","status":"affected","versionType":"git"},{"version":"8bdb3a2d7df48b861972c4bfb58490853a228f51","lessThan":"9e768ae51426af2034d479133cfd73010d641b1a","status":"affected","versionType":"git"},{"version":"8bdb3a2d7df48b861972c4bfb58490853a228f51","lessThan":"de8db23aa7c337e606fca9faf48b3ba72968597a","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/video/fbdev/uvesafb.c"],"versions":[{"version":"2.6.24","status":"affected"},{"version":"0","lessThan":"2.6.24","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.24","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.24","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.24","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.24","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.24","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.24","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.24","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.24","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/b149f77d04082a9da75944cdc488becb0e35258f"},{"url":"https://git.kernel.org/stable/c/0352fdac3cbf11e3b323322ff8cd95e20cbf5cd7"},{"url":"https://git.kernel.org/stable/c/17518e7123f7ef01b1155064dc01f2087583908e"},{"url":"https://git.kernel.org/stable/c/9eb7b3cbe99c9c0edbff69eb155c723e30983c22"},{"url":"https://git.kernel.org/stable/c/9f8a822b44c42502f105cf6574f4867067eecdd0"},{"url":"https://git.kernel.org/stable/c/466a8af0dee2cf745307155e26884e19a37b7e15"},{"url":"https://git.kernel.org/stable/c/9e768ae51426af2034d479133cfd73010d641b1a"},{"url":"https://git.kernel.org/stable/c/de8db23aa7c337e606fca9faf48b3ba72968597a"}],"title":"fbdev: uvesafb: unregister connector callback on init failure","x_generator":{"engine":"bippy-1.2.0"}}}}