Executive brief
A race condition was identified in the Linux kernel's display handling components. This issue affects systems using multiple graphics cards (VGA switcheroo), such as laptops with both integrated and discrete GPUs. An exploit could lead to a system crash or unpredictable display behavior when switching between graphics processors.
Technical details
A race condition exists in the Linux kernel's drm, fbcon, and vga_switcheroo components due to improper locking during framebuffer console (fbcon) setup. Specifically, vga_switcheroo_client_fb_set() was being called before the framebuffer was fully registered, leading to an invalid node value of -1. This causes an out-of-bounds (OOB) access in fbcon_remap_all() when it attempts to use that value as an array index. The vulnerability is triggered during GPU switching operations on systems using amdgpu, i915, nouveau, or radeon drivers. The fix involves moving the vga_switcheroo call under the protection of the console lock within fbcon_fb_registered().
Affected products
- Linux Linux Kernel 2.6.34 to 6.12.60, 6.17.10
Timeline
- 2025-11-05: disclosed: Initial patch submitted by Thomas Zimmermann
- 2025-12-07: patched: Patch committed to stable tree by Greg Kroah-Hartman
- 2025-12-16: advisory: CVE-2025-68296 published