๐Ÿ” CVE Alert

CVE-2026-53402

HIGH 7.1

fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font() When fbcon_do_set_font() fails (e.g., due to a memory allocation failure inside vc_resize() under heavy memory pressure), it jumps to the `err_out` label to roll back the console state. However, the current rollback logic forgets to restore the `hi_font` state, leading to a severe state machine corruption. Earlier in the function, `set_vc_hi_font()` might be called to change `vc->vc_hi_font_mask` and mutate the screen buffer. If `vc_resize()` subsequently fails, the `err_out` path restores `vc_font.charcount` but entirely skips rolling back the `vc_hi_font_mask` and the screen buffer. This mismatch leaves the terminal in a desynchronized state. Because `vc_hi_font_mask` remains set, the VT subsystem will still accept character indices greater than 255 from userspace and write them to the screen buffer. Subsequent rendering calls (e.g., `fbcon_putcs()`) will then use these inflated indices to access the reverted, 256-character font array, leading to a deterministic out-of-bounds read and potential kernel memory disclosure. Fix this by adding the missing rollback logic for the `hi_font` mask and screen buffer in the error path.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 19, 2026
Last Updated Aug 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
868749a7456dc48e93887a8474194e2ee6d6c21f < cb016bcb40c81e7b19c4ae6143babb366dae8e20 ebd6f886aa2447fcfcdce5450c9e1028e1d681bb < ac562193c36696513ae196171892e9338475c4bc a5a923038d70d2d4a86cb4e3f32625a5ee6e7e24 < 3618a4c5b2591cfa83efe74f5b18c2d02b35c3f5 a5a923038d70d2d4a86cb4e3f32625a5ee6e7e24 < a7a526fbc847f07ad3a503c7382189be5ab68574 a5a923038d70d2d4a86cb4e3f32625a5ee6e7e24 < b5bb2c696e140c399cb874def2feedf61dee27d6 a5a923038d70d2d4a86cb4e3f32625a5ee6e7e24 < 076b1aa65f77a49bce5a48a4a55a397cfcafa2b8 a5a923038d70d2d4a86cb4e3f32625a5ee6e7e24 < 39815715cbcfabb16fc8c5f4a23deeda20f5df62 a5a923038d70d2d4a86cb4e3f32625a5ee6e7e24 < 8fdc8c2057eea08d40ce2c8eed41ff9e451c65c2 f08ccb792d3eaf1dc62d8cbf6a30d6522329f660 5.10.249 < 5.10.261 5.15.64 < 5.15.212 5.19.6 < 5.20
Linux / Linux
6.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/cb016bcb40c81e7b19c4ae6143babb366dae8e20 git.kernel.org: https://git.kernel.org/stable/c/ac562193c36696513ae196171892e9338475c4bc git.kernel.org: https://git.kernel.org/stable/c/3618a4c5b2591cfa83efe74f5b18c2d02b35c3f5 git.kernel.org: https://git.kernel.org/stable/c/a7a526fbc847f07ad3a503c7382189be5ab68574 git.kernel.org: https://git.kernel.org/stable/c/b5bb2c696e140c399cb874def2feedf61dee27d6 git.kernel.org: https://git.kernel.org/stable/c/076b1aa65f77a49bce5a48a4a55a397cfcafa2b8 git.kernel.org: https://git.kernel.org/stable/c/39815715cbcfabb16fc8c5f4a23deeda20f5df62 git.kernel.org: https://git.kernel.org/stable/c/8fdc8c2057eea08d40ce2c8eed41ff9e451c65c2