CVE-2026-72266EPSS p10.0%
CVE-2026-72266CVE-2026-72266
Description
In the Linux kernel, the following vulnerability has been resolved:
fbdev: vesafb: fix memory leak in vesafb_probe()
Since commit 73ce73c30ba9 ("fbdev: Transfer video= option strings to
caller; clarify ownership") the string returned from fb_get_options()
is expected to be freed by the caller. But the string is not freed in
vesafb_probe(). Fix that by freeing the option string after setup.
Scoring
| EPSS | 0.21% probability of exploitation · percentile 10.0% · 2026-10-05T12:00:23Z |
| Last modified | 2026-08-17 |