Executive brief
A vulnerability in the Linux kernel's framebuffer console (fbcon) could allow a local user to cause a system crash or potentially gain unauthorized access. The issue occurs when the system attempts to process display mode settings for a console that has not been properly registered. This could lead to operational instability or a complete system shutdown, impacting business continuity.
Technical details
An out-of-bounds array access vulnerability exists in drivers/video/fbdev/core/fbcon.c within the fbcon_info_from_console function. The root cause is an improper validation of the console index in the con2fb_map array, which can contain a value of -1 for unregistered consoles. When a local attacker writes to the 'store_modes' sysfs node, the kernel attempts to use this -1 index to access the fbcon_registered_fb array, triggering a UBSAN array-index-out-of-bounds error. This can result in a kernel oops, denial of service, or potentially local privilege escalation. Patches have been released for various stable kernel branches including 6.1, 6.6, 6.12, and 6.15.
Affected products
- Linux Linux Kernel up to 6.1.142, 6.2 to 6.6.95, 6.7 to 6.12.35, 6.13 to 6.15.4
Timeline
- 2025-05-09: other: Patch authored by Kees Cook
- 2025-07-04: disclosed: CVE published
- 2025-12-18: advisory: NVD enrichment and analysis completed
References
- https://git.kernel.org/stable/c/519ba75728ee8cd561dce25fc52a2ec5c47171dc
- https://git.kernel.org/stable/c/54b28f7c567dd659e5f9562f518e4d7f3f6a367b
- https://git.kernel.org/stable/c/b3237d451bf3a4490cb1a76f3b7c91d9888f1c4b
- https://git.kernel.org/stable/c/cedc1b63394a866bf8663a3e40f4546f1d28c8d8
- https://git.kernel.org/stable/c/f28f1f578cd810779d01999c60618cda14c281dd
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html