PT-2026-61107 · Linux · Linux

CVE-2026-53402

·

Publicado

2026-07-19

·

Atualizado

2026-07-19

CVSS v3.1

7.1

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
In the Linux kernel, the following vulnerability has been resolved:
fbdev: fbcon: fix out-of-bounds read in err out of fbcon do set font()
When fbcon do set font() fails (e.g., due to a memory allocation failure inside vc resize() under heavy memory pressure), it jumps to the err out label to roll back the console state. However, the current rollback logic forgets to restore the hi font state, leading to a severe state machine corruption.
Earlier in the function, set vc hi font() might be called to change vc->vc hi font mask and mutate the screen buffer. If vc resize() subsequently fails, the err out path restores vc font.charcount but entirely skips rolling back the vc hi font mask and the screen buffer.
This mismatch leaves the terminal in a desynchronized state. Because vc hi font mask remains set, the VT subsystem will still accept character indices greater than 255 from userspace and write them to the screen buffer. Subsequent rendering calls (e.g., fbcon putcs()) will then use these inflated indices to access the reverted, 256-character font array, leading to a deterministic out-of-bounds read and potential kernel memory disclosure.
Fix this by adding the missing rollback logic for the hi font mask and screen buffer in the error path.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-53402

Produtos afetados

Linux