REDHAT-BUG-2419870: Medium severity linux/kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved:
fbdev: Add bounds checking in bitputcs to fix vmalloc-out-of-bounds
Add bounds checking to prevent writes past framebuffer boundaries when rendering text near screen edges. Return early if the Y position is off-screen and clip image height to screen boundary. Break from the rendering loop if the X position is off-screen. When clipping image width to fit the screen, update the character count to match the clipped width to prevent buffer size mismatches.
Without the character count update, bitputcsaligned and bitputcsunaligned receive mismatched parameters where the buffer is allocated for the clipped width but cnt reflects the original larger count, causing out-of-bounds writes.
Affected Software
Event History
Frequently Asked Questions
What conditions should be present when investigating a suspected trigger?
Investigate framebuffer text rendering near screen edges, particularly cases where the Y position is off-screen or where the rendered image width or height must be clipped to the framebuffer boundary.
What implementation detail causes the out-of-bounds write?
After clipping width, the rendering buffer can be allocated for the clipped width while the character count still reflects the original larger width. This passes mismatched buffer and count parameters to bit_putcs_aligned or bit_putcs_unaligned, allowing writes beyond the framebuffer boundary.