CVE-2026-72272

medium

Description

In the Linux kernel, the following vulnerability has been resolved: fbdev: radeon: fix potential memory leak in radeonfb_pci_register() The function radeonfb_pci_register() allocates memory for modelist (by calling radeon_check_modes() which calls fb_add_videomode()). The memory is appended to info->modelist, but is not freed in subsequent error paths. Fix this by calling fb_destroy_modelist().

References

https://git.kernel.org/stable/c/f4dacbfd885f34222e67145294de9b8479aa021d

https://git.kernel.org/stable/c/df8c1101c9a08859da612b5d0a08d55d475522c6

https://git.kernel.org/stable/c/c622a3eed6ad26879b6c0bc208fd6e3ffc4b7de3

https://git.kernel.org/stable/c/c2c795a320e7ef9aa69c7f4bd2c9ac07064eff9a

https://git.kernel.org/stable/c/a94a4a0ec2684454934ba104988d6222836a572f

https://git.kernel.org/stable/c/30a2ff955b66b16d4c98dc61f4fe8b3a57c6f7bb

https://git.kernel.org/stable/c/1c5387451176db5def499db809d718765f359a37

https://git.kernel.org/stable/c/1b1b43342fbf11eaf2a8926b9ed4805579d772ac

Details

Source: Mitre, NVD

Published: 2026-08-15

Updated: 2026-08-17

Risk Information

CVSS v2

Base Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.0022