SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-53402

HIGH · CVSS 7.1 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-07-19 · Last synced 2026-08-18

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's framebuffer console (fbcon), where a failure in the `fbcon_do_set_font()` function can lead to an out-of-bounds read due to improper state restoration during error handling. This flaw allows the terminal to accept invalid character indices, potentially leading to kernel memory disclosure. Organizations using Linux systems, particularly those reliant on framebuffer console functionality, should prioritize addressing this vulnerability to mitigate the risk of sensitive data exposure.

CVE
CVE-2026-53402
Severity
HIGH
CVSS
7.1
EPSS
0.14%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font() When fbcon_do_set_font() fails (e.g., due to a memory allocation failure inside vc_resize() under heavy memory pressure), it jumps to the `err_out` label to roll back the console state. However, the current rollback logic forgets to restore the `hi_font` state, leading to a severe state machine corruption. Earlier in the function, `set_vc_hi_font()` might be called to change `vc->vc_hi_font_mask` and mutate the screen buffer. If `vc_resize()` subsequently fails, the `err_out` path restores `vc_font.charcount` but entirely skips rolling back the `vc_hi_font_mask` and the screen buffer. This mismatch leaves the terminal in a desynchronized state. Because `vc_hi_font_mask` remains set, the VT subsystem will still accept character indices greater than 255 from userspace and write them to the screen buffer. Subsequent rendering calls (e.g., `fbcon_putcs()`) will then use these inflated indices to access the reverted, 256-character font array, leading to a deterministic out-of-bounds read and potential kernel memory disclosure. Fix this by adding the missing rollback logic for the `hi_font` mask and screen buffer in the error path.

Related CVEs

Other vulnerabilities affecting the same vendor(s)