๐Ÿ” CVE Alert

CVE-2026-74424

UNKNOWN 0.0

fbcon: fix NULL pointer dereference for a console without vc_data

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: fbcon: fix NULL pointer dereference for a console without vc_data fbcon_new_modelist() runs when a framebuffer's modelist changes. For each console mapped to it with fb_display[i].mode set, it reads vc_cons[i].d and passes the vc_num to fbcon_set_disp(). This assumes a console with a mode set has a vc_data, but it can be NULL. fbcon_set_disp() sets fb_display[i].mode before it checks vc_data, and fbcon_deinit() leaves the mode set after the vc_data is freed. fbcon_new_modelist() then dereferences the NULL vc_data. Keep fb_display[i].mode set only while the console has a vc_data. Check vc_data before setting the mode in fbcon_set_disp(), and clear the mode in fbcon_deinit(). The existing mode check in fbcon_new_modelist() then skips such consoles.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 8e9b8b008f4036df0318870c5d754134ff1b94cc 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < cc4382dc5134826a3936a6b08de17f7dc7abe232 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 9b783b7e03dc78ec102edf618259a2b55911fc6a 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < ac970358c5ca0775841bd2a56ce15dc464b99003 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 6617df8c246311c82cebf061a4cee55b9df60922 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b134ad2f7c06b3c1098dcc95008e2045ff4b49b2 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 5fae9a928482d4845bca169a3a098789203a1ca4 0 < 5.15.212 0 < 6.1.178 0 < 6.6.145 0 < 6.12.97 0 < 6.18.40 0 < 7.1.5
Linux / Linux
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/8e9b8b008f4036df0318870c5d754134ff1b94cc git.kernel.org: https://git.kernel.org/stable/c/cc4382dc5134826a3936a6b08de17f7dc7abe232 git.kernel.org: https://git.kernel.org/stable/c/9b783b7e03dc78ec102edf618259a2b55911fc6a git.kernel.org: https://git.kernel.org/stable/c/ac970358c5ca0775841bd2a56ce15dc464b99003 git.kernel.org: https://git.kernel.org/stable/c/6617df8c246311c82cebf061a4cee55b9df60922 git.kernel.org: https://git.kernel.org/stable/c/b134ad2f7c06b3c1098dcc95008e2045ff4b49b2 git.kernel.org: https://git.kernel.org/stable/c/5fae9a928482d4845bca169a3a098789203a1ca4