« Volver al listado

CVE-2026-53402

Estado: AnalizadaAlta (7.1)—

In the Linux kernel, the following vulnerability has been resolved:

fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()

When fbcon_do_set_font() fails (e.g., due to a memory allocation failure inside vc_resize() under heavy memory pressure), it jumps to the `err_out` label to roll back the console state. However, the current rollback logic forgets to restore the `hi_font` state, leading to a severe state machine corruption.

Earlier in the function, `set_vc_hi_font()` might be called to change `vc->vc_hi_font_mask` and mutate the screen buffer. If `vc_resize()` subsequently fails, the `err_out` path restores `vc_font.charcount` but entirely skips rolling back the `vc_hi_font_mask` and the screen buffer.

Leer descripción completaMostrar menos

This mismatch leaves the terminal in a desynchronized state. Because `vc_hi_font_mask` remains set, the VT subsystem will still accept character indices greater than 255 from userspace and write them to the screen buffer. Subsequent rendering calls (e.g., `fbcon_putcs()`) will then use these inflated indices to access the reverted, 256-character font array, leading to a deterministic out-of-bounds read and potential kernel memory disclosure.

Fix this by adding the missing rollback logic for the `hi_font` mask and screen buffer in the error path.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Acceso local (AV:L) sin interacción del usuario permite escalada mediante corrupción de estado del kernel. El out-of-bounds read en fbcon_putcs() causa lectura de memoria del kernel (T1005/T1552) cuando se usan índices inflados de caracteres.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-53402",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "868749a7456dc48e93887a8474194e2ee6d6c21f",
              "lessThan": "cb016bcb40c81e7b19c4ae6143babb366dae8e20",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ebd6f886aa2447fcfcdce5450c9e1028e1d681bb",
              "lessThan": "ac562193c36696513ae196171892e9338475c4bc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a5a923038d70d2d4a86cb4e3f32625a5ee6e7e24",
              "lessThan": "3618a4c5b2591cfa83efe74f5b18c2d02b35c3f5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a5a923038d70d2d4a86cb4e3f32625a5ee6e7e24",
              "lessThan": "a7a526fbc847f07ad3a503c7382189be5ab68574",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a5a923038d70d2d4a86cb4e3f32625a5ee6e7e24",
              "lessThan": "b5bb2c696e140c399cb874def2feedf61dee27d6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a5a923038d70d2d4a86cb4e3f32625a5ee6e7e24",
              "lessThan": "076b1aa65f77a49bce5a48a4a55a397cfcafa2b8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a5a923038d70d2d4a86cb4e3f32625a5ee6e7e24",
              "lessThan": "39815715cbcfabb16fc8c5f4a23deeda20f5df62",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a5a923038d70d2d4a86cb4e3f32625a5ee6e7e24",
              "lessThan": "8fdc8c2057eea08d40ce2c8eed41ff9e451c65c2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f08ccb792d3eaf1dc62d8cbf6a30d6522329f660",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.10.249",
              "lessThan": "5.10.261",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.15.64",
              "lessThan": "5.15.212",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.19.6",
              "lessThan": "5.20",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/video/fbdev/core/fbcon.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.261",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.212",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.96",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.39",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.3",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/video/fbdev/core/fbcon.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-07-19T12:16:51.387",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/076b1aa65f77a49bce5a48a4a55a397cfcafa2b8",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3618a4c5b2591cfa83efe74f5b18c2d02b35c3f5",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/39815715cbcfabb16fc8c5f4a23deeda20f5df62",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8fdc8c2057eea08d40ce2c8eed41ff9e451c65c2",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a7a526fbc847f07ad3a503c7382189be5ab68574",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ac562193c36696513ae196171892e9338475c4bc",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b5bb2c696e140c399cb874def2feedf61dee27d6",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cb016bcb40c81e7b19c4ae6143babb366dae8e20",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-125"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()\n\nWhen fbcon_do_set_font() fails (e.g., due to a memory allocation failure\ninside vc_resize() under heavy memory pressure), it jumps to the `err_out`\nlabel to roll back the console state. However, the current rollback logic\nforgets to restore the `hi_font` state, leading to a severe state machine\ncorruption.\n\nEarlier in the function, `set_vc_hi_font()` might be called to change\n`vc->vc_hi_font_mask` and mutate the screen buffer. If `vc_resize()`\nsubsequently fails, the `err_out` path restores `vc_font.charcount`\nbut entirely skips rolling back the `vc_hi_font_mask` and the screen\nbuffer.\n\nThis mismatch leaves the terminal in a desynchronized state. Because\n`vc_hi_font_mask` remains set, the VT subsystem will still accept\ncharacter indices greater than 255 from userspace and write them to the\nscreen buffer. Subsequent rendering calls (e.g., `fbcon_putcs()`) will\nthen use these inflated indices to access the reverted, 256-character\nfont array, leading to a deterministic out-of-bounds read and potential\nkernel memory disclosure.\n\nFix this by adding the missing rollback logic for the `hi_font` mask\nand screen buffer in the error path."
    }
  ],
  "lastModified": "2026-08-17T05:17:15.080",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B7E36D96-72CA-4974-A809-29C9A2541071",
              "versionEndExcluding": "5.10.261",
              "versionStartIncluding": "5.10.249"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0D866C5E-CE49-4FE6-9E1A-F7E438921074",
              "versionEndExcluding": "5.15.212",
              "versionStartIncluding": "5.15.64"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E53B030-2C91-45B9-91A0-63E897460E68",
              "versionEndExcluding": "6.0",
              "versionStartIncluding": "5.19.6"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "22C9EAD8-0845-4C82-A958-43F2EDB3B88D",
              "versionEndExcluding": "6.1.178",
              "versionStartIncluding": "6.0.1"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7046B092-F810-4440-ACE6-60218518EECE",
              "versionEndExcluding": "6.6.145",
              "versionStartIncluding": "6.2"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "38A8100E-2B1A-462F-AEE9-8901B870FEF2",
              "versionEndExcluding": "6.12.96",
              "versionStartIncluding": "6.7"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "914AE4BC-3D59-4C5A-9DB5-9CE327B429F7",
              "versionEndExcluding": "6.18.39",
              "versionStartIncluding": "6.13"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9526B150-E2B3-4C6F-8AE5-1AF92B75AD9E",
              "versionEndExcluding": "7.1.3",
              "versionStartIncluding": "6.19"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7BE551E5-89CF-47A8-9B26-03CE727FBA37"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.0:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A46498B3-78E1-4623-AAE1-94D29A42BE4E"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.0:rc4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F8446E87-F5F6-41CA-8201-BAE0F0CA6DD9"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.0:rc5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8E5FB72F-67CE-43CC-83FE-541604D98182"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.0:rc6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3A0A7397-F5F8-4753-82DC-9A11288E696D"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.0:rc7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E6DE049A-ABA8-41DD-988C-8C088358EE9B"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}