---
id: CVE-2026-89597
title: >-
  kernel: fbdev: uvesafb: unregister connector callback on init failure
  (CVE-2026-89597)
summary: >-
  A flaw was found in the `uvesafb` component of the Linux kernel. During the
  initialization process, if the platform driver fails to register, a connector
  callback is not properly unregistered. This oversight can lead to a resource
  leak, wh…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-772
vendor: Red Hat
product: Linux
affected:
  - >-
    Linux >= 8bdb3a2d7df48b861972c4bfb58490853a228f51 <
    b149f77d04082a9da75944cdc488becb0e35258f
  - >-
    Linux >= 8bdb3a2d7df48b861972c4bfb58490853a228f51 <
    0352fdac3cbf11e3b323322ff8cd95e20cbf5cd7
  - >-
    Linux >= 8bdb3a2d7df48b861972c4bfb58490853a228f51 <
    17518e7123f7ef01b1155064dc01f2087583908e
  - >-
    Linux >= 8bdb3a2d7df48b861972c4bfb58490853a228f51 <
    9eb7b3cbe99c9c0edbff69eb155c723e30983c22
  - >-
    Linux >= 8bdb3a2d7df48b861972c4bfb58490853a228f51 <
    9f8a822b44c42502f105cf6574f4867067eecdd0
  - >-
    Linux >= 8bdb3a2d7df48b861972c4bfb58490853a228f51 <
    466a8af0dee2cf745307155e26884e19a37b7e15
  - >-
    Linux >= 8bdb3a2d7df48b861972c4bfb58490853a228f51 <
    9e768ae51426af2034d479133cfd73010d641b1a
  - >-
    Linux >= 8bdb3a2d7df48b861972c4bfb58490853a228f51 <
    de8db23aa7c337e606fca9faf48b3ba72968597a
  - Linux 2.6.24
published: '2026-09-11'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T22:12:34+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89597.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89597.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-89597'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532247'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-89597'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89597'
  - url: >-
      https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89597.mbox
  - url: 'https://git.kernel.org/stable/c/b149f77d04082a9da75944cdc488becb0e35258f'
  - url: 'https://git.kernel.org/stable/c/0352fdac3cbf11e3b323322ff8cd95e20cbf5cd7'
  - url: 'https://git.kernel.org/stable/c/17518e7123f7ef01b1155064dc01f2087583908e'
  - url: 'https://git.kernel.org/stable/c/9eb7b3cbe99c9c0edbff69eb155c723e30983c22'
  - url: 'https://git.kernel.org/stable/c/9f8a822b44c42502f105cf6574f4867067eecdd0'
  - url: 'https://git.kernel.org/stable/c/466a8af0dee2cf745307155e26884e19a37b7e15'
  - url: 'https://git.kernel.org/stable/c/9e768ae51426af2034d479133cfd73010d641b1a'
  - url: 'https://git.kernel.org/stable/c/de8db23aa7c337e606fca9faf48b3ba72968597a'
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
  - score-dispute
epss: 0.00176
epssPercentile: 0.06284
scores:
  vendor: 5.5
  cna: 7.8
ingestedAt: '2026-09-14T15:23:07.451Z'
---

## Overview

A flaw was found in the `uvesafb` component of the Linux kernel. During the initialization process, if the platform driver fails to register, a connector callback is not properly unregistered. This oversight can lead to a resource leak, which may result in system instability or a denial of service (DoS) condition.

## Vendor advisories

- **Red Hat VEX** · Moderate · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89597.json)

**kernel: fbdev: uvesafb: unregister connector callback on init failure** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-18.

Not affected:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4

## Remediation

Refer to the advisory for fix availability.
