Executive brief
A vulnerability in the Linux kernel's framebuffer console (fbcon) could allow a local user to cause a system crash or potentially execute unauthorized code. The issue occurs when the system fails to properly resize memory buffers while rotating the screen display. If this memory reallocation fails, the system continues using an undersized buffer, leading to a memory overflow when text is printed to the screen.
Technical details
An out-of-bounds (OOB) memory access vulnerability exists in the Linux kernel's framebuffer console driver (fbcon). The root cause is located in the `fbcon_rotate_font()` function, which fails to clear or invalidate the existing font buffer if a reallocation attempt fails during a console rotation operation. Because the driver retains the original buffer—which is too small for the rotated font—subsequent calls to `putcs` implementations using high-value character codes will result in a buffer overflow. This is a local attack vector requiring the ability to trigger console rotation and print characters. Patches have been released across multiple stable kernel branches to ensure the font buffer is cleared if reallocation fails.
Affected products
- Linux Linux kernel v2.6.15 to v6.19
Timeline
- 2026-04-07: patched: Initial fix in main kernel tree
- 2026-05-28: disclosed: CVE published
References
- https://git.kernel.org/stable/c/594973a2e54924d8ba31c9faac669fc1ba6fcb80
- https://git.kernel.org/stable/c/7105d9f1387d63b15c9a860674fc92c959181f2f
- https://git.kernel.org/stable/c/ab6c34b9829d5de03f1d08a47a2253729a6e7e27
- https://git.kernel.org/stable/c/b44cc78ff46b96e72d333a3be6aaaa0a14797263
- https://git.kernel.org/stable/c/e4ef723d8975a2694cc90733a6b888a5e2841842