PT-2025-17666 · Linux+4 · Linux Kernel+4

Published

2025-04-23

·

Updated

2026-05-26

·

CVE-2025-40322

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel’s fbdev component related to bitblit operations and glyph indexing within the bit putcs function. Specifically, the glyph pointer calculation in bit putcs aligned() and bit putcs unaligned() did not adequately bound-check the glyph index, potentially leading to an out-of-bounds read when accessing the built-in font array. This occurs when the character value, masked, results in an index exceeding the font’s actual glyph count. The issue was identified by syzbot.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALSA-2026:1661
ALSA-2026:1662
ALSA-2026:2282
ALSA-2026:2722
CVE-2025-40322
DLA-4404-1
ECHO-CE2F-B1C4-FC57
MGASA-2026-0017
MGASA-2026-0018
OESA-2025-2852
OESA-2026-1231
OESA-2026-1303
OESA-2026-1304
OESA-2026-1305
OPENSUSE-SU-2026:20145-1
RHSA-2026:1661
RHSA-2026:1662
RHSA-2026:1727
RHSA-2026:2282
RHSA-2026:2352
RHSA-2026:2490
RHSA-2026:2535
RHSA-2026:2560
RHSA-2026:2573
RHSA-2026:2577
RHSA-2026:2583
RHSA-2026:2594
RHSA-2026:2664
RHSA-2026:2722
RHSA-2026:3360
SUSE-SU-2026:0278-1
SUSE-SU-2026:0281-1
SUSE-SU-2026:0293-1
SUSE-SU-2026:0315-1
SUSE-SU-2026:0316-1
SUSE-SU-2026:20207-1
SUSE-SU-2026:20220-1
SUSE-SU-2026:20228-1
SUSE-SU-2026:20477-1
SUSE-SU-2026:20498-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1
USN-8029-1
USN-8029-2
USN-8029-3
USN-8030-1
USN-8048-1
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8096-1
USN-8096-2
USN-8096-3
USN-8096-4
USN-8096-5
USN-8100-1
USN-8116-1
USN-8125-1
USN-8126-1
USN-8141-1
USN-8163-1
USN-8163-2
USN-8165-1
USN-8243-1
USN-8261-1

Affected Products

Debian
Linuxmint
Linux Kernel
Rocky Linux
Ubuntu