CVE-2026-80578
In the Linux kernel, the following vulnerability has been resolved:
fbdev: core: Fix pointer desynchronization in fb_io_read()
In fb_io_read(), if copy_to_user() performs a partial copy (e.g., due to a faulty user buffer), the loop adjusts the chunk size 'c' and updates the remaining 'count'. However, the hardware 'src' pointer has already been eagerly advanced by the original chunk size.
If the loop is allowed to continue, the read will resume from an incorrect, over-advanced offset. Since the remaining 'count' was only decremented by the successful bytes, this desynchronization causes the next iterations to execute more hardware reads than originally bounded, eventually leading to out-of-bounds I/O reads.
Leer descripción completaMostrar menos
Fix this by breaking out of the loop immediately upon a partial copy_to_user(). A partial copy indicates a faulty user buffer, making subsequent read attempts futile. Breaking out ensures we return the number of successfully read bytes without risking out-of-bounds hardware accesses in subsequent mismatched iterations.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
- Puntuación base: 7.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 5
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1005Data from Local Systemcollection90 %
Vulnerabilidad en kernel de Linux (acceso local, PR:L) que permite leer más allá de límites de memoria mediante desincronización de punteros en fb_io_read(), causando lecturas de datos no autorizadas.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/42a6d8126c194133eafab2b0fd5c8668ebfcba5b
- https://git.kernel.org/stable/c/42bc07b4e5a3c8a02a433388f562a8f46d093e11
- https://git.kernel.org/stable/c/7110b7b794a2aac2c5cf8eb06ebf2af724c74d50
- https://git.kernel.org/stable/c/7ff87a01ae3a8cd0208f7499386998223a8b5dba
- https://git.kernel.org/stable/c/81cc73be40c6f028f1ee3f438ace46afe666dbae
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-80578",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.3,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.5,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6121cd9ef911432b14c2a17aefaf8cd2f3cfcdff",
"lessThan": "42bc07b4e5a3c8a02a433388f562a8f46d093e11",
"versionType": "git"
},
{
"status": "affected",
"version": "6121cd9ef911432b14c2a17aefaf8cd2f3cfcdff",
"lessThan": "42a6d8126c194133eafab2b0fd5c8668ebfcba5b",
"versionType": "git"
},
{
"status": "affected",
"version": "6121cd9ef911432b14c2a17aefaf8cd2f3cfcdff",
"lessThan": "7ff87a01ae3a8cd0208f7499386998223a8b5dba",
"versionType": "git"
},
{
"status": "affected",
"version": "6121cd9ef911432b14c2a17aefaf8cd2f3cfcdff",
"lessThan": "7110b7b794a2aac2c5cf8eb06ebf2af724c74d50",
"versionType": "git"
},
{
"status": "affected",
"version": "6121cd9ef911432b14c2a17aefaf8cd2f3cfcdff",
"lessThan": "81cc73be40c6f028f1ee3f438ace46afe666dbae",
"versionType": "git"
}
],
"programFiles": [
"drivers/video/fbdev/core/fb_io_fops.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.5"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.5",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/video/fbdev/core/fb_io_fops.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-26T15:17:13.880",
"references": [
{
"url": "https://git.kernel.org/stable/c/42a6d8126c194133eafab2b0fd5c8668ebfcba5b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/42bc07b4e5a3c8a02a433388f562a8f46d093e11",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7110b7b794a2aac2c5cf8eb06ebf2af724c74d50",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7ff87a01ae3a8cd0208f7499386998223a8b5dba",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/81cc73be40c6f028f1ee3f438ace46afe666dbae",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: core: Fix pointer desynchronization in fb_io_read()\n\nIn fb_io_read(), if copy_to_user() performs a partial copy (e.g., due to\na faulty user buffer), the loop adjusts the chunk size 'c' and updates\nthe remaining 'count'. However, the hardware 'src' pointer has already\nbeen eagerly advanced by the original chunk size.\n\nIf the loop is allowed to continue, the read will resume from an\nincorrect, over-advanced offset. Since the remaining 'count' was only\ndecremented by the successful bytes, this desynchronization causes the\nnext iterations to execute more hardware reads than originally bounded,\neventually leading to out-of-bounds I/O reads.\n\nFix this by breaking out of the loop immediately upon a partial\ncopy_to_user(). A partial copy indicates a faulty user buffer, making\nsubsequent read attempts futile. Breaking out ensures we return the\nnumber of successfully read bytes without risking out-of-bounds hardware\naccesses in subsequent mismatched iterations."
}
],
"lastModified": "2026-08-27T06:17:43.823",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}