PT-2026-61107 · Linux · Linux
CVE-2026-53402
·
Publicado
2026-07-19
·
Atualizado
2026-07-19
CVSS v3.1
7.1
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
In the Linux kernel, the following vulnerability has been resolved:
fbdev: fbcon: fix out-of-bounds read in err out of fbcon do set font()
When fbcon do set font() fails (e.g., due to a memory allocation failure
inside vc resize() under heavy memory pressure), it jumps to the
err out
label to roll back the console state. However, the current rollback logic
forgets to restore the hi font state, leading to a severe state machine
corruption.Earlier in the function,
set vc hi font() might be called to change
vc->vc hi font mask and mutate the screen buffer. If vc resize()
subsequently fails, the err out path restores vc font.charcount
but entirely skips rolling back the vc hi font mask and the screen
buffer.This mismatch leaves the terminal in a desynchronized state. Because
vc hi font mask remains set, the VT subsystem will still accept
character indices greater than 255 from userspace and write them to the
screen buffer. Subsequent rendering calls (e.g., fbcon putcs()) will
then use these inflated indices to access the reverted, 256-character
font array, leading to a deterministic out-of-bounds read and potential
kernel memory disclosure.Fix this by adding the missing rollback logic for the
hi font mask
and screen buffer in the error path.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux