In the Linux kernel, the following vulnerability has been resolved: video: fbdev: vesafb: Fix a use-after-free due early fbinfo cleanup Commit b3c9a924aab6 ("fbdev: vesafb: Cleanup fbinfo in .fbdestroy rather than .remove") fixed a use-after-free error due the vesafb driver freeing the fbinfo in the .remove handler instead of doing it in .fbdestroy. This can happen if the .fbdestroy callback is executed after the .remove callback, since the former tries to access a pointer freed by the latter. But that change didn't take into account that another possible scenario is that .fbdestroy is called before the .remove callback. For example, if no process has the fbdev chardev opened by the time the driver is removed. If that's the case, fbinfo will be freed when unregisterframebuffer() is called, making the fbinfo pointer accessed in vesafbremove() after that to no longer be valid. To prevent that, move the expression containing the info->par to happen before the unregisterframebuffer() function call.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "linux-buildinfo-5.15.0-1015-intel-iotg", "binary_version": "5.15.0-1015.20" }, { "binary_name": "linux-cloud-tools-5.15.0-1015-intel-iotg", "binary_version": "5.15.0-1015.20" }, { "binary_name": "linux-headers-5.15.0-1015-intel-iotg", "binary_version": "5.15.0-1015.20" }, { "binary_name": "linux-image-unsigned-5.15.0-1015-intel-iotg", "binary_version": "5.15.0-1015.20" }, { "binary_name": "linux-image-unsigned-5.15.0-1015-intel-iotg-dbgsym", "binary_version": "5.15.0-1015.20" }, { "binary_name": "linux-intel-iotg-cloud-tools-5.15.0-1015", "binary_version": "5.15.0-1015.20" }, { "binary_name": "linux-intel-iotg-cloud-tools-common", "binary_version": "5.15.0-1015.20" }, { "binary_name": "linux-intel-iotg-headers-5.15.0-1015", "binary_version": "5.15.0-1015.20" }, { "binary_name": "linux-intel-iotg-tools-5.15.0-1015", "binary_version": "5.15.0-1015.20" }, { "binary_name": "linux-intel-iotg-tools-common", "binary_version": "5.15.0-1015.20" }, { "binary_name": "linux-intel-iotg-tools-host", "binary_version": "5.15.0-1015.20" }, { "binary_name": "linux-modules-5.15.0-1015-intel-iotg", "binary_version": "5.15.0-1015.20" }, { "binary_name": "linux-modules-extra-5.15.0-1015-intel-iotg", "binary_version": "5.15.0-1015.20" }, { "binary_name": "linux-modules-iwlwifi-5.15.0-1015-intel-iotg", "binary_version": "5.15.0-1015.20" }, { "binary_name": "linux-tools-5.15.0-1015-intel-iotg", "binary_version": "5.15.0-1015.20" } ] }