Executive brief
A vulnerability was found in the Linux kernel's auxiliary display driver framework, which manages small character-based screens. A local user could trigger a system crash or cause the display to behave unexpectedly by sending a specially crafted empty message to the device's control file. This issue primarily impacts system stability and the availability of the connected display hardware.
Technical details
An out-of-bounds (OOB) read exists in the `linedisp_display()` function within `drivers/auxdisplay/line-display.c`. The function unconditionally accesses `msg[count - 1]` to check for a trailing newline before verifying if `count` is zero. When a user writes zero bytes to the `message` sysfs attribute, `count` is 0, causing an access to `msg[-1]`. In KASAN-enabled kernels, this results in a kernel panic; on standard kernels, it reads adjacent slab data. If the leaked byte happens to be a newline character, `count` underflows to -1, which is subsequently passed to `kmemdup_nul()`, leading to further memory safety issues. The vulnerability affects drivers using the `linedisp` core, including ht16k33, max6959, img-ascii-lcd, and seg-led-gpio. Patches have been released across multiple stable kernel branches.
Affected products
- Linux Linux Kernel 7e76aece6f03 to ca5b0781946d
Timeline
- 2026-05-14: other: Vulnerability fixed in source code
- 2026-07-19: disclosed: CVE published
References
- https://git.kernel.org/stable/c/197476b126010bac1b3199833c6966cd6f54c2a9
- https://git.kernel.org/stable/c/3859960daeb9b7b39b9847b5b0113bc6081eb735
- https://git.kernel.org/stable/c/6ad4f75ef9f3372fce8cad494e789ac6a5507bef
- https://git.kernel.org/stable/c/8776032fe989a9b5fc77f2de5e03e4adb44c630e
- https://git.kernel.org/stable/c/a7511dcd9dd4bc55d123f9b800c8a4ed2662e5c6
- https://git.kernel.org/stable/c/ca5b0781946d5083ceafa752141f47f085853620