Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-63826

Published Jul 19, 2026 EPSS 0.17% (6th pctl)

Overview

CVE-2026-63826 is a known-severity vulnerability. It was published on July 19, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

fbdev: fix use-after-free in store_modes()

store_modes() replaces a framebuffer's modelist with modes from userspace.

On success it frees the old modelist with fb_destroy_modelist(). Two

fields still point into that freed list.

One pointer is fb_display[i].mode, the mode a console is using.

fbcon_new_modelist() moves these pointers to the new list. It only does so

for consoles still mapped to the framebuffer. An unmapped console is

skipped and keeps its stale pointer. Unbinding fbcon, for example, sets

con2fb_map[i] to -1 but leaves fb_display[i].mode set. An

FBIOPUT_VSCREENINFO ioctl with FB_ACTIVATE_INV_MODE later reaches

fbcon_mode_deleted(). That function reads the stale fb_display[i].mode

through fb_mode_is_equal(). The read is a use-after-free.

The other pointer is fb_info->mode, the current mode. It is set through

the mode sysfs attribute. store_modes() does not update fb_info->mode, so

it is left pointing i

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-63826?

CVE-2026-63826 is a known-severity vulnerability. It was published on July 19, 2026.

How severe is CVE-2026-63826?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-63826?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-63826?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-63826 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.