Executive brief
A vulnerability exists in the Linux kernel's framebuffer console (fbcon) component, which manages how text is displayed on the screen. By providing specially crafted font parameters, a local user could trigger an internal calculation error that leads to memory corruption. This could allow an attacker to crash the system or potentially gain elevated privileges, compromising the security and stability of the operating system.
Technical details
An integer overflow vulnerability exists in the `fbcon_do_set_font()` function within `drivers/video/fbdev/core/fbcon.c`. The flaw is triggered when calculating the font size using the `CALC_FONTSZ(h, pitch, charcount)` macro and subsequent additions for extra words, where user-controlled values for height, pitch, and character count can cause the result to wrap around. This leads to an undersized memory allocation via `kmalloc()`, resulting in a heap-based buffer overflow when font data is copied into the buffer. The vulnerability is reachable by local users with permissions to change console fonts. Patches have been released across multiple stable kernel branches (e.g., 6.11.y, 6.6.y, 6.1.y, 5.15.y, 5.10.y, 5.4.y) utilizing `check_mul_overflow()` and `check_add_overflow()` to validate calculations.
Affected products
- Linux Linux Kernel v5.9 to v6.11.y (and various stable branches)
Timeline
- 2025-09-12: disclosed: Initial patch submission by Samasth Norway Ananda
- 2025-10-02: patched: Patches committed to various stable kernel trees
- 2025-10-15: advisory: CVE-2025-39967 published
References
- https://git.kernel.org/stable/c/1a194e6c8e1ee745e914b0b7f50fa86c89ed13fe
- https://git.kernel.org/stable/c/4a4bac869560f943edbe3c2b032062f6673b13d3
- https://git.kernel.org/stable/c/994bdc2d23c79087fbf7dcd9544454e8ebcef877
- https://git.kernel.org/stable/c/9c8ec14075c5317edd6b242f1be8167aa1e4e333
- https://git.kernel.org/stable/c/a6eb9f423b3db000aaedf83367b8539f6b72dcfc
- https://git.kernel.org/stable/c/adac90bb1aaf45ca66f9db8ac100be16750ace78
- https://git.kernel.org/stable/c/b8a6e85328aeb9881531dbe89bcd2637a06c3c95