AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-72273

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability exists in the Linux kernel's framebuffer device (fbdev) subsystem, specifically within the efifb_probe() function, which fails to free a memory string allocated during setup. This oversight can lead to a memory leak, potentially affecting system performance and stability over time. Linux system administrators and developers should prioritize addressing this issue to ensure optimal resource management and prevent potential denial-of-service conditions.

CVE
CVE-2026-72273
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: fbdev: efifb: fix memory leak in efifb_probe() Since commit 73ce73c30ba9 ("fbdev: Transfer video= option strings to caller; clarify ownership") the string returned from fb_get_options() is expected to be freed by the caller, but the string is not freed in efifb_probe(). Fix that by freeing the option string after setup.