Executive brief
A vulnerability in the Linux kernel's console display driver could allow a local user to view sensitive information stored in the system's memory. The issue occurs when the system fails to properly reset its internal state after a failed attempt to change console fonts, such as during periods of high memory pressure. This can lead to a situation where the system reads data from outside the intended memory boundaries, potentially exposing private data to an unauthorized user.
Technical details
An out-of-bounds read vulnerability exists in the Linux kernel's fbdev/fbcon component within the fbcon_do_set_font() function. When this function encounters a failure (such as a memory allocation failure in vc_resize()), the error handling path fails to roll back the 'hi_font' mask state. This results in a desynchronized state where the Virtual Terminal (VT) subsystem accepts character indices greater than 255 while the font array has been reverted to a 256-character limit. A local attacker can exploit this mismatch to trigger an out-of-bounds read during rendering calls like fbcon_putcs(), potentially leading to the disclosure of sensitive kernel memory. The issue has been patched by ensuring the hi_font mask and screen buffer are correctly restored in the error path.
Affected products
- Linux Linux Kernel 5.10.249, 5.15.64, 5.19.6, and others up to 6.10.y
Timeline
- 2026-06-25: patched: Initial fix committed to Linux kernel mainline
- 2026-07-19: disclosed: CVE published to NVD dataset