From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1B250388394 for ; Sat, 15 Aug 2026 06:40:56 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786776057; cv=none; b=bRzu0n6A0BHqzO2z5KFi7H3FXPqmVKefmCKoBhj0f7GGDGQcxiIAQGND2J4l++8UkzOMTZv2Txhct72RgVzWamIb0gTZU0s2C1iwWnYAUoQHKOysQ2rAhCguGQsiZeJOl0Tjq7LrRQ8ITzej7RLnYc7e+7WQWkepE1SBh2kRcc4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786776057; c=relaxed/simple; bh=ve3KuE6Z7q+tV5jAfGin99OPj352TnczeDJTn5UjW20=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=kw5ub2TAWSR7IwjyZ3/QtuLztSDJ55E/UkbYUqA6qjaKTkk0yVdFy3ou5lzncCnQL6g40BtXsxUfp6QuumskThuToUM3NHWBiZboLNVTmInyjnx7y1PD5vdE7kw+Don0w/SBbqc8F+2+z++OosIbq9o5qo8hmoMD6eVac8+VV/A= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=op5xvggh; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="op5xvggh" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 6EEB11F000E9; Sat, 15 Aug 2026 06:40:55 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1786776056; bh=6qneQWH01BR0mwjiC2CgcF0fyTOjFkU9q7TMvIBKndw=; h=From:To:Cc:Subject:Date:Reply-To; b=op5xvgghY9nxTIoPOj2n/u5+5+qZp6cOcigmOUlgQn9SVrZ3TGZo+zhEs5ObN0pDc Qa2l9Y9nj1jC/nyxN8Mc3cWSp/RwD91vinyYR+uZ5mrmou6LUUpHn1tWdKX2JXuWMx sgsxLIqFcFpQ+SCwdBKVokLVjjUPQMyPmKK/cAvQ= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-74424: fbcon: fix NULL pointer dereference for a console without vc_data Date: Sat, 15 Aug 2026 15:12:31 +0900 Message-ID: <2026081513-CVE-2026-74424-2cab@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3057; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=eJtn9uo8ajRCENraZ6eVz5TvcMnTL0DVCKGzDpftL9Q=; b=owGbwMvMwCRo6H6F97bub03G02pJDFkNjIo54vvsJe77cay7Gx2f4zpTs9Da/bRNSKC95QfH9 e8m74jviGVhEGRikBVTZPmyjefo/opDil6Gtqdh5rAygQxh4OIUgImcP86wYPu5UgaeQh+D5IUz HnY6lO3159lziGGulLLxrvLjLzav17x20WAzw5duYft6AA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: fbcon: fix NULL pointer dereference for a console without vc_data fbcon_new_modelist() runs when a framebuffer's modelist changes. For each console mapped to it with fb_display[i].mode set, it reads vc_cons[i].d and passes the vc_num to fbcon_set_disp(). This assumes a console with a mode set has a vc_data, but it can be NULL. fbcon_set_disp() sets fb_display[i].mode before it checks vc_data, and fbcon_deinit() leaves the mode set after the vc_data is freed. fbcon_new_modelist() then dereferences the NULL vc_data. Keep fb_display[i].mode set only while the console has a vc_data. Check vc_data before setting the mode in fbcon_set_disp(), and clear the mode in fbcon_deinit(). The existing mode check in fbcon_new_modelist() then skips such consoles. The Linux kernel CVE team has assigned CVE-2026-74424 to this issue. Affected and fixed versions =========================== Fixed in 5.15.212 with commit 8e9b8b008f4036df0318870c5d754134ff1b94cc Fixed in 6.1.178 with commit cc4382dc5134826a3936a6b08de17f7dc7abe232 Fixed in 6.6.145 with commit 9b783b7e03dc78ec102edf618259a2b55911fc6a Fixed in 6.12.97 with commit ac970358c5ca0775841bd2a56ce15dc464b99003 Fixed in 6.18.40 with commit 6617df8c246311c82cebf061a4cee55b9df60922 Fixed in 7.1.5 with commit b134ad2f7c06b3c1098dcc95008e2045ff4b49b2 Fixed in 7.2-rc1 with commit 5fae9a928482d4845bca169a3a098789203a1ca4 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-74424 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/video/fbdev/core/fbcon.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/8e9b8b008f4036df0318870c5d754134ff1b94cc https://git.kernel.org/stable/c/cc4382dc5134826a3936a6b08de17f7dc7abe232 https://git.kernel.org/stable/c/9b783b7e03dc78ec102edf618259a2b55911fc6a https://git.kernel.org/stable/c/ac970358c5ca0775841bd2a56ce15dc464b99003 https://git.kernel.org/stable/c/6617df8c246311c82cebf061a4cee55b9df60922 https://git.kernel.org/stable/c/b134ad2f7c06b3c1098dcc95008e2045ff4b49b2 https://git.kernel.org/stable/c/5fae9a928482d4845bca169a3a098789203a1ca4