Linux kernel CVE announcements
 help / color / mirror / Atom feed
From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-cve-announce@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@kernel.org>
Subject: CVE-2026-74424: fbcon: fix NULL pointer dereference for a console without vc_data
Date: Sat, 15 Aug 2026 15:12:31 +0900	[thread overview]
Message-ID: <2026081513-CVE-2026-74424-2cab@gregkh> (raw)

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

fbcon: fix NULL pointer dereference for a console without vc_data

fbcon_new_modelist() runs when a framebuffer's modelist changes. For each
console mapped to it with fb_display[i].mode set, it reads vc_cons[i].d and
passes the vc_num to fbcon_set_disp(). This assumes a console with a mode
set has a vc_data, but it can be NULL. fbcon_set_disp() sets
fb_display[i].mode before it checks vc_data, and fbcon_deinit() leaves the
mode set after the vc_data is freed. fbcon_new_modelist() then dereferences
the NULL vc_data.

Keep fb_display[i].mode set only while the console has a vc_data. Check
vc_data before setting the mode in fbcon_set_disp(), and clear the mode in
fbcon_deinit(). The existing mode check in fbcon_new_modelist() then skips
such consoles.

The Linux kernel CVE team has assigned CVE-2026-74424 to this issue.


Affected and fixed versions
===========================

	Fixed in 5.15.212 with commit 8e9b8b008f4036df0318870c5d754134ff1b94cc
	Fixed in 6.1.178 with commit cc4382dc5134826a3936a6b08de17f7dc7abe232
	Fixed in 6.6.145 with commit 9b783b7e03dc78ec102edf618259a2b55911fc6a
	Fixed in 6.12.97 with commit ac970358c5ca0775841bd2a56ce15dc464b99003
	Fixed in 6.18.40 with commit 6617df8c246311c82cebf061a4cee55b9df60922
	Fixed in 7.1.5 with commit b134ad2f7c06b3c1098dcc95008e2045ff4b49b2
	Fixed in 7.2-rc1 with commit 5fae9a928482d4845bca169a3a098789203a1ca4

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-74424
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/video/fbdev/core/fbcon.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/8e9b8b008f4036df0318870c5d754134ff1b94cc
	https://git.kernel.org/stable/c/cc4382dc5134826a3936a6b08de17f7dc7abe232
	https://git.kernel.org/stable/c/9b783b7e03dc78ec102edf618259a2b55911fc6a
	https://git.kernel.org/stable/c/ac970358c5ca0775841bd2a56ce15dc464b99003
	https://git.kernel.org/stable/c/6617df8c246311c82cebf061a4cee55b9df60922
	https://git.kernel.org/stable/c/b134ad2f7c06b3c1098dcc95008e2045ff4b49b2
	https://git.kernel.org/stable/c/5fae9a928482d4845bca169a3a098789203a1ca4

                 reply	other threads:[~2026-08-15  6:40 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2026081513-CVE-2026-74424-2cab@gregkh \
    --to=gregkh@linuxfoundation.org \
    --cc=cve@kernel.org \
    --cc=gregkh@kernel.org \
    --cc=linux-cve-announce@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox