๐Ÿ” CVE Alert

CVE-2026-63949

UNKNOWN 0.0

auxdisplay: line-display: fix OOB read on zero-length message_store()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: auxdisplay: line-display: fix OOB read on zero-length message_store() linedisp_display() unconditionally reads msg[count - 1] before checking whether count is zero, so a write of zero bytes to the message sysfs attribute hits msg[-1]: write(fd, "", 0); -> message_store(..., buf, count=0) -> linedisp_display(linedisp, buf, count=0) -> msg[count - 1] == '\n' ; OOB read The kernfs write buffer for that store is a 1-byte allocation (kernfs_fop_write_iter() does kmalloc(len + 1) with len == 0), so msg[-1] is a 1-byte read before the slab object. On a KASAN-enabled kernel this trips an out-of-bounds report and panics; on stock kernels it silently reads adjacent slab data and, if that byte happens to be '\n', the following count-- wraps ssize_t 0 to -1 and is then passed to kmemdup_nul(). linedisp_display() is reached from the message_store() sysfs callback (drivers/auxdisplay/line-display.c message attribute, mode 0644) and from the in-tree initial-message setup with count == -1, so the OOB path is only userspace-triggerable via zero-byte writes; vfs_write() does not short-circuit on count == 0 and kernfs_fop_write_iter() dispatches the store callback regardless. Guard the trailing-newline trim with a count check. The existing if (!count) block then takes the clear-display path unchanged. Affects every auxdisplay driver that registers via linedisp_register() / linedisp_attach(): ht16k33, max6959, img-ascii-lcd, seg-led-gpio.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 19, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
7e76aece6f036cb7ada4858d6aa73825bfe22983 < ca5b0781946d5083ceafa752141f47f085853620 7e76aece6f036cb7ada4858d6aa73825bfe22983 < 8776032fe989a9b5fc77f2de5e03e4adb44c630e 7e76aece6f036cb7ada4858d6aa73825bfe22983 < 3859960daeb9b7b39b9847b5b0113bc6081eb735 7e76aece6f036cb7ada4858d6aa73825bfe22983 < 197476b126010bac1b3199833c6966cd6f54c2a9 7e76aece6f036cb7ada4858d6aa73825bfe22983 < 6ad4f75ef9f3372fce8cad494e789ac6a5507bef 7e76aece6f036cb7ada4858d6aa73825bfe22983 < a7511dcd9dd4bc55d123f9b800c8a4ed2662e5c6
Linux / Linux
5.16

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/ca5b0781946d5083ceafa752141f47f085853620 git.kernel.org: https://git.kernel.org/stable/c/8776032fe989a9b5fc77f2de5e03e4adb44c630e git.kernel.org: https://git.kernel.org/stable/c/3859960daeb9b7b39b9847b5b0113bc6081eb735 git.kernel.org: https://git.kernel.org/stable/c/197476b126010bac1b3199833c6966cd6f54c2a9 git.kernel.org: https://git.kernel.org/stable/c/6ad4f75ef9f3372fce8cad494e789ac6a5507bef git.kernel.org: https://git.kernel.org/stable/c/a7511dcd9dd4bc55d123f9b800c8a4ed2662e5c6