An issue was discovered in set_con2fb_map in drivers/video/fbdev/core/fbcon.c in the Linux kernel before 6.2.12. Because an assignment occurs only for the first vc, the fbcon_registered_fb and fbcon_display arrays can be desynchronized in fbcon_mode_deleted (the con2fb_map points at the old fb_info)..This CVE has a CVSS3.1 score of 7.2 and a Base Severity of HIGH.
Info | Details |
---|---|
CVE ID | CVE-2023-38409 |
CVE State | PUBLISHED |
BaseScore | NA |
BaseSeverity | NA |
VectorString | NA |
Version | NA |
References for CVE-2023-38409 :
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit?id=fffb0b52d5258554c645c966c6cbef7de50b851d
https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.2.12
Metric Type | Metric Score |
---|---|
AttackVector(AV) | NA |
AttackComplexity(AC) | NA |
PrivilegesRequired(PR) | NA |
UserInteraction(UI) | NA |
Scope(S) | NA |
Confidentiality(C) | NA |
Availability(A) | NA |
Integrity(I) | NA |