CVE-2026-53402: fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()
fbdev: fbcon: fix out-of-bounds read in errout of fbcondosetfont()
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.145.2-1 - Upgrade
Upgrade
Linux kernel fbdev: fbconto a version that resolves this vulnerability.Patch fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53402?
The severity of CVE-2026-53402 is high, with a CVSS score of 7.1.
What issue does CVE-2026-53402 address?
CVE-2026-53402 addresses an out-of-bounds read vulnerability in the Linux kernel related to the fbcon_do_set_font() function.
How do I fix CVE-2026-53402?
To fix CVE-2026-53402, update the Linux kernel to the patched version that addresses the vulnerability.
What software is affected by CVE-2026-53402?
CVE-2026-53402 affects the Linux kernel specifically in the fbdev subsystem.
What could happen if CVE-2026-53402 is exploited?
If exploited, CVE-2026-53402 could lead to a denial of service due to potential application crashes.