* CVE-2026-74424: fbcon: fix NULL pointer dereference for a console without vc_data
@ 2026-08-15 6:12 Greg Kroah-Hartman
0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-08-15 6:12 UTC (permalink / raw)
To: linux-cve-announce; +Cc: Greg Kroah-Hartman
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
fbcon: fix NULL pointer dereference for a console without vc_data
fbcon_new_modelist() runs when a framebuffer's modelist changes. For each
console mapped to it with fb_display[i].mode set, it reads vc_cons[i].d and
passes the vc_num to fbcon_set_disp(). This assumes a console with a mode
set has a vc_data, but it can be NULL. fbcon_set_disp() sets
fb_display[i].mode before it checks vc_data, and fbcon_deinit() leaves the
mode set after the vc_data is freed. fbcon_new_modelist() then dereferences
the NULL vc_data.
Keep fb_display[i].mode set only while the console has a vc_data. Check
vc_data before setting the mode in fbcon_set_disp(), and clear the mode in
fbcon_deinit(). The existing mode check in fbcon_new_modelist() then skips
such consoles.
The Linux kernel CVE team has assigned CVE-2026-74424 to this issue.
Affected and fixed versions
===========================
Fixed in 5.15.212 with commit 8e9b8b008f4036df0318870c5d754134ff1b94cc
Fixed in 6.1.178 with commit cc4382dc5134826a3936a6b08de17f7dc7abe232
Fixed in 6.6.145 with commit 9b783b7e03dc78ec102edf618259a2b55911fc6a
Fixed in 6.12.97 with commit ac970358c5ca0775841bd2a56ce15dc464b99003
Fixed in 6.18.40 with commit 6617df8c246311c82cebf061a4cee55b9df60922
Fixed in 7.1.5 with commit b134ad2f7c06b3c1098dcc95008e2045ff4b49b2
Fixed in 7.2-rc1 with commit 5fae9a928482d4845bca169a3a098789203a1ca4
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-74424
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
drivers/video/fbdev/core/fbcon.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/8e9b8b008f4036df0318870c5d754134ff1b94cc
https://git.kernel.org/stable/c/cc4382dc5134826a3936a6b08de17f7dc7abe232
https://git.kernel.org/stable/c/9b783b7e03dc78ec102edf618259a2b55911fc6a
https://git.kernel.org/stable/c/ac970358c5ca0775841bd2a56ce15dc464b99003
https://git.kernel.org/stable/c/6617df8c246311c82cebf061a4cee55b9df60922
https://git.kernel.org/stable/c/b134ad2f7c06b3c1098dcc95008e2045ff4b49b2
https://git.kernel.org/stable/c/5fae9a928482d4845bca169a3a098789203a1ca4
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-08-15 6:40 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-15 6:12 CVE-2026-74424: fbcon: fix NULL pointer dereference for a console without vc_data Greg Kroah-Hartman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.