-

CVE-2026-63949

auxdisplay: line-display: fix OOB read on zero-length message_store()

In the Linux kernel, the following vulnerability has been resolved:

auxdisplay: line-display: fix OOB read on zero-length message_store()

linedisp_display() unconditionally reads msg[count - 1] before
checking whether count is zero, so a write of zero bytes to the
message sysfs attribute hits msg[-1]:

	write(fd, "", 0);

	-> message_store(..., buf, count=0)
	   -> linedisp_display(linedisp, buf, count=0)
	      -> msg[count - 1] == '\n'  ; OOB read

The kernfs write buffer for that store is a 1-byte allocation
(kernfs_fop_write_iter() does kmalloc(len + 1) with len == 0),
so msg[-1] is a 1-byte read before the slab object. On a
KASAN-enabled kernel this trips an out-of-bounds report and
panics; on stock kernels it silently reads adjacent slab data
and, if that byte happens to be '\n', the following count--
wraps ssize_t 0 to -1 and is then passed to kmemdup_nul().

linedisp_display() is reached from the message_store() sysfs
callback (drivers/auxdisplay/line-display.c message attribute,
mode 0644) and from the in-tree initial-message setup with
count == -1, so the OOB path is only userspace-triggerable via
zero-byte writes; vfs_write() does not short-circuit on
count == 0 and kernfs_fop_write_iter() dispatches the store
callback regardless.

Guard the trailing-newline trim with a count check. The
existing if (!count) block then takes the clear-display path
unchanged.

Affects every auxdisplay driver that registers via
linedisp_register() / linedisp_attach(): ht16k33, max6959,
img-ascii-lcd, seg-led-gpio.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 7e76aece6f036cb7ada4858d6aa73825bfe22983
Version < ca5b0781946d5083ceafa752141f47f085853620
Status affected
Version 7e76aece6f036cb7ada4858d6aa73825bfe22983
Version < 8776032fe989a9b5fc77f2de5e03e4adb44c630e
Status affected
Version 7e76aece6f036cb7ada4858d6aa73825bfe22983
Version < 3859960daeb9b7b39b9847b5b0113bc6081eb735
Status affected
Version 7e76aece6f036cb7ada4858d6aa73825bfe22983
Version < 197476b126010bac1b3199833c6966cd6f54c2a9
Status affected
Version 7e76aece6f036cb7ada4858d6aa73825bfe22983
Version < 6ad4f75ef9f3372fce8cad494e789ac6a5507bef
Status affected
Version 7e76aece6f036cb7ada4858d6aa73825bfe22983
Version < a7511dcd9dd4bc55d123f9b800c8a4ed2662e5c6
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 5.16
Status affected
Version 0
Version < 5.16
Status unaffected
Version <= 6.1.*
Version 6.1.176
Status unaffected
Version <= 6.6.*
Version 6.6.143
Status unaffected
Version <= 6.12.*
Version 6.12.93
Status unaffected
Version <= 6.18.*
Version 6.18.35
Status unaffected
Version <= 7.0.*
Version 7.0.12
Status unaffected
Version <= *
Version 7.1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.069
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/ca5b0781946d5083ceafa752141f47f085853620
https://git.kernel.org/stable/c/8776032fe989a9b5fc77f2de5e03e4adb44c630e
https://git.kernel.org/stable/c/3859960daeb9b7b39b9847b5b0113bc6081eb735
https://git.kernel.org/stable/c/197476b126010bac1b3199833c6966cd6f54c2a9
https://git.kernel.org/stable/c/6ad4f75ef9f3372fce8cad494e789ac6a5507bef
https://git.kernel.org/stable/c/a7511dcd9dd4bc55d123f9b800c8a4ed2662e5c6