PT-2025-25874 · Linux+2 · Linux Kernel+2

Published

2022-08-30

·

Updated

2025-08-18

·

CVE-2022-49948

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue arises when changing the console font with ioctl(KDFONTOP), where the new font size can be larger than the previous one. This can lead to out-of-bounds accesses to graphics memory if a previous selection is removed in vc do resize(). The problem occurs because the previous selection may now be outside of the new screen size.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02254
CVE-2022-49948
OESA-2025-1820
SUSE-SU-2025:02264-1
SUSE-SU-2025:02308-1
SUSE-SU-2025:02320-1
SUSE-SU-2025:02321-1
SUSE-SU-2025:02322-1
SUSE-SU-2025:02537-1
SUSE-SU-2025:02846-1
SUSE-SU-2025:2264-1
SUSE-SU-2025_02264-1
SUSE-SU-2025_02308-1
SUSE-SU-2025_02537-1
SUSE-SU-2025_02846-1

Affected Products

Astra Linux
Linux Kernel
Suse