7.1

CVE-2026-53402

fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()

In the Linux kernel, the following vulnerability has been resolved:

fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()

When fbcon_do_set_font() fails (e.g., due to a memory allocation failure
inside vc_resize() under heavy memory pressure), it jumps to the `err_out`
label to roll back the console state. However, the current rollback logic
forgets to restore the `hi_font` state, leading to a severe state machine
corruption.

Earlier in the function, `set_vc_hi_font()` might be called to change
`vc->vc_hi_font_mask` and mutate the screen buffer. If `vc_resize()`
subsequently fails, the `err_out` path restores `vc_font.charcount`
but entirely skips rolling back the `vc_hi_font_mask` and the screen
buffer.

This mismatch leaves the terminal in a desynchronized state. Because
`vc_hi_font_mask` remains set, the VT subsystem will still accept
character indices greater than 255 from userspace and write them to the
screen buffer. Subsequent rendering calls (e.g., `fbcon_putcs()`) will
then use these inflated indices to access the reverted, 256-character
font array, leading to a deterministic out-of-bounds read and potential
kernel memory disclosure.

Fix this by adding the missing rollback logic for the `hi_font` mask
and screen buffer in the error path.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version >= 5.10.249 < 5.10.261
LinuxLinux Kernel Version >= 5.15.64 < 5.15.212
LinuxLinux Kernel Version >= 5.19.6 < 6.0
LinuxLinux Kernel Version >= 6.0.1 < 6.1.178
LinuxLinux Kernel Version >= 6.2 < 6.6.145
LinuxLinux Kernel Version >= 6.7 < 6.12.96
LinuxLinux Kernel Version >= 6.13 < 6.18.39
LinuxLinux Kernel Version >= 6.19 < 7.1.3
LinuxLinux Kernel Version6.0 Update-
LinuxLinux Kernel Version6.0 Updaterc3
LinuxLinux Kernel Version6.0 Updaterc4
LinuxLinux Kernel Version6.0 Updaterc5
LinuxLinux Kernel Version6.0 Updaterc6
LinuxLinux Kernel Version6.0 Updaterc7
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.034
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

https://git.kernel.org/stable/c/b5bb2c696e140c399cb874def2feedf61dee27d6
Patch
https://git.kernel.org/stable/c/076b1aa65f77a49bce5a48a4a55a397cfcafa2b8
Patch
https://git.kernel.org/stable/c/39815715cbcfabb16fc8c5f4a23deeda20f5df62
Patch
https://git.kernel.org/stable/c/8fdc8c2057eea08d40ce2c8eed41ff9e451c65c2
Patch
https://git.kernel.org/stable/c/3618a4c5b2591cfa83efe74f5b18c2d02b35c3f5
Patch
https://git.kernel.org/stable/c/a7a526fbc847f07ad3a503c7382189be5ab68574
Patch
https://git.kernel.org/stable/c/ac562193c36696513ae196171892e9338475c4bc
Patch
https://git.kernel.org/stable/c/cb016bcb40c81e7b19c4ae6143babb366dae8e20
Patch