5.5

CVE-2026-53385

vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write

In the Linux kernel, the following vulnerability has been resolved:

vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write

A KASAN null-ptr-deref was observed in vcs_notifier():

BUG: KASAN: null-ptr-deref in vcs_notifier+0x98/0x130
Read of size 2 at addr qmp_cmd_name: qmp_capabilities, arguments: {}

The issue is a race condition in vcs_write(). When the console_lock is
temporarily dropped (to copy data from userspace), the vc_data pointer
obtained from vcs_vc() may become stale. After re-acquiring the lock,
vcs_vc() is called again to re-validate the pointer. If the vc has been
deallocated in the meantime, vcs_vc() returns NULL, and the while loop
breaks (with written > 0). However, after the loop, vcs_scr_updated(vc)
is still called with the now-NULL vc pointer, leading to a null pointer
dereference in the notifier chain (vcs_notifier dereferences param->vc).

Fix this by adding a NULL check for vc before calling vcs_scr_updated().
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version >= 4.14.327 < 4.15
LinuxLinux Kernel Version >= 4.19.284 < 4.20
LinuxLinux Kernel Version >= 5.4.244 < 5.5
LinuxLinux Kernel Version >= 5.10.181 < 5.10.260
LinuxLinux Kernel Version >= 5.15.113 < 5.15.211
LinuxLinux Kernel Version >= 6.1.30 < 6.1.177
LinuxLinux Kernel Version >= 6.3.4 < 6.4
LinuxLinux Kernel Version >= 6.4.1 < 6.6.144
LinuxLinux Kernel Version >= 6.7 < 6.12.95
LinuxLinux Kernel Version >= 6.13 < 6.18.37
LinuxLinux Kernel Version >= 6.19 < 7.0.14
LinuxLinux Kernel Version >= 7.1 < 7.1.2
LinuxLinux Kernel Version6.4 Update-
LinuxLinux Kernel Version6.4 Updaterc3
LinuxLinux Kernel Version6.4 Updaterc4
LinuxLinux Kernel Version6.4 Updaterc5
LinuxLinux Kernel Version6.4 Updaterc6
LinuxLinux Kernel Version6.4 Updaterc7
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.032
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://git.kernel.org/stable/c/43a6281790273c1b0a9ab76609ff0245b968f1e6
Patch
https://git.kernel.org/stable/c/b6bbb85cf45bf0b070e741997fe0af3a772c5ad5
Patch
https://git.kernel.org/stable/c/ff4806202749a51938236214adc0281481a57366
Patch
https://git.kernel.org/stable/c/8232fca738011ca2ec865b46ec721d1796dc0580
Patch
https://git.kernel.org/stable/c/73049768ad57145acd337102c5aa3c788e6642c8
Patch
https://git.kernel.org/stable/c/7cc3dd79777f6ae4625ec37e84dd18a26dc88bde
Patch
https://git.kernel.org/stable/c/74be188eb2dc1c99d63986167b9a67d415fe7326
Patch
https://git.kernel.org/stable/c/09a43e81279b8da15526da09877134b8bcf618b0
Patch
https://git.kernel.org/stable/c/a287620312dc6dcb9a093417a0e589bf30fcf38a
Patch