Executive brief
A vulnerability in the Linux kernel's frame buffer device (fbdev) could allow a local user to cause a system crash or potentially execute unauthorized code. The issue occurs when the system fails to properly handle screen resizing during console mapping, leading to memory corruption. This could impact the stability of industrial controllers and servers, potentially leading to service outages or unauthorized data access.
Technical details
An out-of-bounds (OOB) write vulnerability exists in the Linux kernel's fbdev core (drivers/video/fbdev/core/fbcon.c) within the fast_imageblit function. The flaw is triggered via the FBIOPUT_CON2FBMAP ioctl when a userspace program attempts to map a console to a frame buffer. If the console resize operation (vc_do_resize) fails, the kernel incorrectly continues the mapping process using inconsistent display variables and console data from the previous frame buffer. This state mismatch leads to an OOB write when the screen is subsequently updated via fbcon_putcs(). A local attacker with basic user privileges can exploit this to cause a denial of service (system crash) or potentially achieve privilege escalation. Patches have been released across multiple stable kernel branches.
Affected products
- Linux Linux Kernel All versions prior to fixed stable releases (6.10.7, 6.6.48, 6.1.107, 5.15.166, 5.10.225, 5.4.283, 4.19.321)
- Siemens SIMATIC CN 4100 Versions prior to V5.0
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5 and later versions prior to patch
Timeline
- 2025-07-31: disclosed: Vulnerability reported and fix authored
- 2025-08-28: patched: Fix committed to stable kernel trees
- 2025-09-04: advisory: CVE published in NVD
References
- https://git.kernel.org/stable/c/078e62bffca4b7e72e8f3550eb063ab981c36c7a
- https://git.kernel.org/stable/c/27b118aebdd84161c8ff5ce49d9d536f2af10754
- https://git.kernel.org/stable/c/4c4d7ddaf1d43780b106bedc692679f965dc5a3a
- https://git.kernel.org/stable/c/56701bf9eeb63219e378cb7fcbd066ea4eaeeb50
- https://git.kernel.org/stable/c/af0db3c1f898144846d4c172531a199bb3ca375d
- https://git.kernel.org/stable/c/cfec17721265e72e50cc69c6004fe3475cd38df2
- https://git.kernel.org/stable/c/ed9b8e5016230868c8d813d9179523f729fec8c6