PT-2025-42242 · Linux+4 · Linux Kernel+4

Published

2025-09-22

·

Updated

2026-05-07

·

CVE-2025-39967

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the Linux kernel’s fbcon do set font() function where integer overflows can occur during font size calculations when handling user-controlled font parameters. Specifically, overflows can happen in the following calculations: the multiplication of h, pitch, and charcount within CALC FONTSZ(h, pitch, charcount), and the addition of FONT EXTRA WORDS * sizeof(int) to size. These overflows can lead to smaller-than-expected memory allocations, resulting in buffer overflows during font data copying. The issue is addressed by adding explicit overflow checking using the check mul overflow() and check add overflow() kernel helpers to validate size calculations before allocation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Integer Overflow

Weakness Enumeration

Related Identifiers

AZL-68468
AZL-76440
BDU:2026-02705
CVE-2025-39967
DLA-4379-1
DLA-4404-1
DSA-6053-1
ECHO-AFD3-684E-0232
MGASA-2025-0309
MGASA-2025-0310
OESA-2025-2551
OESA-2025-2552
OESA-2025-2556
OESA-2026-1569
OPENSUSE-SU-2025:20091-1
SUSE-SU-2025:21040-1
SUSE-SU-2025:21052-1
SUSE-SU-2025:21056-1
SUSE-SU-2025:21064-1
SUSE-SU-2025:21080-1
SUSE-SU-2025:21147-1
SUSE-SU-2025:21180-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4111-1
SUSE-SU-2025:4128-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4139-1
SUSE-SU-2025:4140-1
SUSE-SU-2025:4141-1
SUSE-SU-2025:4149-1
SUSE-SU-2025:4301-1
SUSE-SU-2025:4320-1
SUSE-SU-2025:4515-1
SUSE-SU-2026:0029-1
SUSE-SU-2026:0033-1
USN-8033-1
USN-8033-2
USN-8033-3
USN-8033-4
USN-8033-5
USN-8033-6
USN-8033-7
USN-8033-8
USN-8034-1
USN-8034-2
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8141-1
USN-8163-1
USN-8163-2
USN-8165-1
USN-8243-1
USN-8261-1

Affected Products

Debian
Linuxmint
Linux Kernel
Suse
Ubuntu