Executive brief
A vulnerability in the Linux kernel's virtual terminal component can lead to memory corruption when deleting characters on the screen. This issue affects the way text is handled in the system console, potentially causing system instability or minor service disruptions. While the impact is primarily limited to availability, it represents a flaw in core system software used across many Linux distributions.
Technical details
A vulnerability exists in the Linux kernel's virtual terminal (vt) driver, specifically within the `vc_uniscr_delete` function in `drivers/tty/vt/vt.c`. The issue stems from the use of `memcpy()` to handle overlapping memory regions when shifting characters in the Unicode screen buffer during a delete operation. According to the C standard, `memcpy()` behavior is undefined when source and destination buffers overlap; this can lead to memory corruption. The fix replaces `memcpy()` with `memmove()`, which is designed to safely handle overlapping memory regions. An attacker could potentially trigger this corruption to cause a denial-of-service (system crash or terminal instability). The vulnerability has been patched in multiple stable kernel branches including 4.19.312, 5.4.274, 5.10.215, 5.15.154, 6.1.84, 6.6.24, and 6.7.12.
Affected products
- Linux Linux Kernel 3.7 to 4.19.312, 4.20 to 5.4.274, 5.5 to 5.10.215, 5.11 to 5.15.154, 5.16 to 6.1.84, 6.2 to 6.6.24, 6.7 to 6.7.12, 6.8.x
Timeline
- 2024-02-29: patched: Initial fix authored by Nicolas Pitre
- 2024-05-17: disclosed: CVE-2024-35823 published
References
- https://git.kernel.org/stable/c/0190d19d7651c08abc187dac3819c61b726e7e3f
- https://git.kernel.org/stable/c/1581dafaf0d34bc9c428a794a22110d7046d186d
- https://git.kernel.org/stable/c/1ce408f75ccf1e25b3fddef75cca878b55f2ac90
- https://git.kernel.org/stable/c/2933b1e4757a0a5c689cf48d80b1a2a85f237ff1
- https://git.kernel.org/stable/c/7529cbd8b5f6697b369803fe1533612c039cabda
- https://git.kernel.org/stable/c/994a1e583c0c206c8ca7d03334a65b79f4d8bc51
- https://git.kernel.org/stable/c/fc7dfe3d123f00e720be80b920da287810a1f37d