CVE-2026-89597
Received Received - Intake

uvesafb Connector Callback Unregistration Failure in Linux Kernel

Vulnerability report for CVE-2026-89597, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: fbdev: uvesafb: unregister connector callback on init failure uvesafb_init() registers the v86d connector callback before registering the platform driver. If platform_driver_register() fails, the function returns the error directly and leaves the connector callback registered. The later platform-device failure path already unregisters the callback. Add the same cleanup before the final return when platform-driver registration fails. This issue was identified during our ongoing static-analysis research while reviewing kernel code.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves the uvesafb component. During initialization, the function uvesafb_init() registers a connector callback before the platform driver is registered. If the platform driver registration fails, the function exits without unregistering the callback, leaving it active. This creates a cleanup issue where the callback remains registered despite the driver failing to initialize.

Detection Guidance

This vulnerability is specific to the Linux kernel's fbdev subsystem and does not have network-based detection methods. To check if your system is affected, verify the kernel version and inspect the uvesafb module for the described issue. Use commands like 'uname -a' to check the kernel version and 'lsmod | grep uvesafb' to see if the module is loaded.

Impact Analysis

This vulnerability could lead to system instability or resource leaks if the uvesafb component fails to initialize properly. The lingering connector callback might cause unexpected behavior or errors in the kernel, potentially affecting system operations that rely on the fbdev subsystem.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards. It is a local kernel driver issue that could lead to resource leaks but does not involve data exposure or privacy violations typical of compliance concerns.

Mitigation Strategies

Apply the latest kernel updates from your Linux distribution to ensure the vulnerability is patched. If you are using a custom kernel, recompile it with the fix for the uvesafb module. Monitor kernel security advisories for updates related to this issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89597. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart