CVE-2026-53385
In the Linux kernel, the following vulnerability has been resolved:
vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write
A KASAN null-ptr-deref was observed in vcs_notifier():
The issue is a race condition in vcs_write(). When the console_lock is temporarily dropped (to copy data from userspace), the vc_data pointer obtained from vcs_vc() may become stale. After re-acquiring the lock, vcs_vc() is called again to re-validate the pointer. If the vc has been deallocated in the meantime, vcs_vc() returns NULL, and the while loop breaks (with written > 0). However, after the loop, vcs_scr_updated(vc) is still called with the now-NULL vc pointer, leading to a null pointer dereference in the notifier chain (vcs_notifier dereferences param->vc).
Leer descripción completaMostrar menos
Fix this by adding a NULL check for vc before calling vcs_scr_updated().
Detalles técnicos trazas, registros y código del informe original
BUG: KASAN: null-ptr-deref in vcs_notifier+0x98/0x130
Read of size 2 at addr qmp_cmd_name: qmp_capabilities, arguments: {}CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.13%
- Percentil entre todas las CVEs puntuadas: 2
- Fecha de la puntuación: 3/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-476
Referencias
- https://git.kernel.org/stable/c/09a43e81279b8da15526da09877134b8bcf618b0
- https://git.kernel.org/stable/c/43a6281790273c1b0a9ab76609ff0245b968f1e6
- https://git.kernel.org/stable/c/73049768ad57145acd337102c5aa3c788e6642c8
- https://git.kernel.org/stable/c/74be188eb2dc1c99d63986167b9a67d415fe7326
- https://git.kernel.org/stable/c/7cc3dd79777f6ae4625ec37e84dd18a26dc88bde
- https://git.kernel.org/stable/c/8232fca738011ca2ec865b46ec721d1796dc0580
- https://git.kernel.org/stable/c/a287620312dc6dcb9a093417a0e589bf30fcf38a
- https://git.kernel.org/stable/c/b6bbb85cf45bf0b070e741997fe0af3a772c5ad5
- https://git.kernel.org/stable/c/ff4806202749a51938236214adc0281481a57366
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-53385",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "11dddfbb7a4e62489b01074d6c04d9d1b42e4047",
"lessThan": "43a6281790273c1b0a9ab76609ff0245b968f1e6",
"versionType": "git"
},
{
"status": "affected",
"version": "e3d1adcad5b73c7ed0c7edb35ab68abcaa45cf67",
"lessThan": "b6bbb85cf45bf0b070e741997fe0af3a772c5ad5",
"versionType": "git"
},
{
"status": "affected",
"version": "3338d0b9acde770ee588eead5cac32c25e7048fc",
"lessThan": "ff4806202749a51938236214adc0281481a57366",
"versionType": "git"
},
{
"status": "affected",
"version": "8fb9ea65c9d1338b0d2bb0a9122dc942cdd32357",
"lessThan": "8232fca738011ca2ec865b46ec721d1796dc0580",
"versionType": "git"
},
{
"status": "affected",
"version": "8fb9ea65c9d1338b0d2bb0a9122dc942cdd32357",
"lessThan": "73049768ad57145acd337102c5aa3c788e6642c8",
"versionType": "git"
},
{
"status": "affected",
"version": "8fb9ea65c9d1338b0d2bb0a9122dc942cdd32357",
"lessThan": "7cc3dd79777f6ae4625ec37e84dd18a26dc88bde",
"versionType": "git"
},
{
"status": "affected",
"version": "8fb9ea65c9d1338b0d2bb0a9122dc942cdd32357",
"lessThan": "74be188eb2dc1c99d63986167b9a67d415fe7326",
"versionType": "git"
},
{
"status": "affected",
"version": "8fb9ea65c9d1338b0d2bb0a9122dc942cdd32357",
"lessThan": "09a43e81279b8da15526da09877134b8bcf618b0",
"versionType": "git"
},
{
"status": "affected",
"version": "8fb9ea65c9d1338b0d2bb0a9122dc942cdd32357",
"lessThan": "a287620312dc6dcb9a093417a0e589bf30fcf38a",
"versionType": "git"
},
{
"status": "affected",
"version": "934de9a9b659785fed3e820bc0c813a460c71fea",
"versionType": "git"
},
{
"status": "affected",
"version": "0deff678157333d775af190f84696336cdcccd6d",
"versionType": "git"
},
{
"status": "affected",
"version": "a4e3c4c65ae8510e01352c9a4347e05c035b2ce2",
"versionType": "git"
},
{
"status": "affected",
"version": "1de42e7653d6714a7507ba6696151a1fa028c69f",
"versionType": "git"
},
{
"status": "affected",
"version": "5.10.181",
"lessThan": "5.10.260",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.15.113",
"lessThan": "5.15.211",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.1.30",
"lessThan": "6.1.177",
"versionType": "semver"
},
{
"status": "affected",
"version": "4.14.327",
"lessThan": "4.15",
"versionType": "semver"
},
{
"status": "affected",
"version": "4.19.284",
"lessThan": "4.20",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.4.244",
"lessThan": "5.5",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.3.4",
"lessThan": "6.4",
"versionType": "semver"
}
],
"programFiles": [
"drivers/tty/vt/vc_screen.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.4",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.260",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.211",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.177",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.144",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.95",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.37",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.0.14",
"versionType": "semver",
"lessThanOrEqual": "7.0.*"
},
{
"status": "unaffected",
"version": "7.1.2",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/tty/vt/vc_screen.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-07-19T12:16:49.387",
"references": [
{
"url": "https://git.kernel.org/stable/c/09a43e81279b8da15526da09877134b8bcf618b0",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/43a6281790273c1b0a9ab76609ff0245b968f1e6",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/73049768ad57145acd337102c5aa3c788e6642c8",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/74be188eb2dc1c99d63986167b9a67d415fe7326",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7cc3dd79777f6ae4625ec37e84dd18a26dc88bde",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8232fca738011ca2ec865b46ec721d1796dc0580",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a287620312dc6dcb9a093417a0e589bf30fcf38a",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b6bbb85cf45bf0b070e741997fe0af3a772c5ad5",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ff4806202749a51938236214adc0281481a57366",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-476"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write\n\nA KASAN null-ptr-deref was observed in vcs_notifier():\n\nBUG: KASAN: null-ptr-deref in vcs_notifier+0x98/0x130\nRead of size 2 at addr qmp_cmd_name: qmp_capabilities, arguments: {}\n\nThe issue is a race condition in vcs_write(). When the console_lock is\ntemporarily dropped (to copy data from userspace), the vc_data pointer\nobtained from vcs_vc() may become stale. After re-acquiring the lock,\nvcs_vc() is called again to re-validate the pointer. If the vc has been\ndeallocated in the meantime, vcs_vc() returns NULL, and the while loop\nbreaks (with written > 0). However, after the loop, vcs_scr_updated(vc)\nis still called with the now-NULL vc pointer, leading to a null pointer\ndereference in the notifier chain (vcs_notifier dereferences param->vc).\n\nFix this by adding a NULL check for vc before calling vcs_scr_updated()."
}
],
"lastModified": "2026-08-17T05:17:12.580",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "57F7B207-E013-4478-81D8-3F12A2BAEFAA",
"versionEndExcluding": "4.15",
"versionStartIncluding": "4.14.327"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C1A386C5-AE2D-42FC-B649-6AABE8B95E96",
"versionEndExcluding": "4.20",
"versionStartIncluding": "4.19.284"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AB0EBA89-EB7A-4BB3-B042-444DA36A04AC",
"versionEndExcluding": "5.5",
"versionStartIncluding": "5.4.244"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EA706F3D-EA53-4DDB-BD14-28E38D892972",
"versionEndExcluding": "5.10.260",
"versionStartIncluding": "5.10.181"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "91670A7F-B99D-4690-BD53-0F85E077EC40",
"versionEndExcluding": "5.15.211",
"versionStartIncluding": "5.15.113"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4107FECC-519B-46B5-8A94-748F4E5BE6B3",
"versionEndExcluding": "6.1.177",
"versionStartIncluding": "6.1.30"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A1C4BF07-55E0-4ECE-B2BC-1C398FA64210",
"versionEndExcluding": "6.4",
"versionStartIncluding": "6.3.4"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1FB20250-D599-4124-9B31-4ACBD815386B",
"versionEndExcluding": "6.6.144",
"versionStartIncluding": "6.4.1"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4E206B86-E0E3-4394-A93F-39F2D50A8AA8",
"versionEndExcluding": "6.12.95",
"versionStartIncluding": "6.7"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E08ACB05-518A-4D61-A6C4-268D1BB6BF46",
"versionEndExcluding": "6.18.37",
"versionStartIncluding": "6.13"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6241DF06-E6F3-4B61-B5A2-A60F2AE5B982",
"versionEndExcluding": "7.0.14",
"versionStartIncluding": "6.19"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C18FAA06-B61A-4036-A12D-F06F5135E64B",
"versionEndExcluding": "7.1.2",
"versionStartIncluding": "7.1"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.4:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DE0B0BF6-0EEF-4FAD-927D-7A0DD77BEE75"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.4:rc3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A717BA5B-D535-46A0-A329-A25FE5CEC588"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.4:rc4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "89CC80C6-F1EE-4AC7-BD21-DB3217BADE87"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.4:rc5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "41EACEA1-FB69-4AF2-BC52-D39489858D42"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.4:rc6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9E1C36BE-F9D8-40B6-8281-5B8F9B42322D"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.4:rc7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1D6CAA59-F0EF-4E0B-8C23-EC9535008572"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}