CVE-2022-49948
published 2025-06-18CVE-2022-49948: In the Linux kernel, the following vulnerability has been resolved: vt: Clear selection before changing the font When changing the console font with…
PriorityP429high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.21%
11.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
vt: Clear selection before changing the font
When changing the console font with ioctl(KDFONTOP) the new font size
can be bigger than the previous font. A previous selection may thus now
be outside of the new screen size and thus trigger out-of-bounds
accesses to graphics memory if the selection is removed in
vc_do_resize().
Prevent such out-of-memory accesses by dropping the selection before the
various con_font_set() console handlers are called.
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.2-1 (bookworm) | linux 6.0.2-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 009e39ae44f4191188aeb6dfbf661b771dbbe515 < c555cf04684fde39b5b0dd9fd80730030ee10c4a | c555cf04684fde39b5b0dd9fd80730030ee10c4a |
| linux | linux | >= 009e39ae44f4191188aeb6dfbf661b771dbbe515 < e9ba4611ddf676194385506222cce7b0844e708e | e9ba4611ddf676194385506222cce7b0844e708e |
| linux | linux | >= 009e39ae44f4191188aeb6dfbf661b771dbbe515 < f74b4a41c5d7c9522469917e3072e55d435efd9e | f74b4a41c5d7c9522469917e3072e55d435efd9e |
| linux | linux | >= 009e39ae44f4191188aeb6dfbf661b771dbbe515 < 1cf1930369c9dc428d827b60260c53271bff3285 | 1cf1930369c9dc428d827b60260c53271bff3285 |
| linux | linux | >= 009e39ae44f4191188aeb6dfbf661b771dbbe515 < 989201bb8c00b222235aff04e6200230d29dc7bb | 989201bb8c00b222235aff04e6200230d29dc7bb |
| linux | linux | >= 009e39ae44f4191188aeb6dfbf661b771dbbe515 < 2535431ae967ad17585513649625fea7db28d4db | 2535431ae967ad17585513649625fea7db28d4db |
| linux | linux | >= 009e39ae44f4191188aeb6dfbf661b771dbbe515 < c904fe03c4bd1f356a58797d39e2a5d0ca15cefc | c904fe03c4bd1f356a58797d39e2a5d0ca15cefc |
| linux | linux | >= 009e39ae44f4191188aeb6dfbf661b771dbbe515 < 566f9c9f89337792070b5a6062dff448b3e7977f | 566f9c9f89337792070b5a6062dff448b3e7977f |
| linux | linux | >= 3.10.105 < 3.11 | 3.11 |
| linux | linux | >= 3.12.68 < 3.13 | 3.13 |
| linux | linux | >= 3.16.40 < 3.17 | 3.17 |
| linux | linux | >= 3.18.45 < 3.19 | 3.19 |
| linux | linux | >= 3.2.85 < 3.3 | 3.3 |
| linux | linux | >= 4.1.36 < 4.2 | 4.2 |
| linux | linux | >= 4.4.31 < 4.5 | 4.5 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2022-49948: In the Linux kernel, the following vulnerability has been resolved: vt: Clear selection before changing the font When changing the console font with i
osv·2025-06-18·CVSS 7.1
CVE-2022-49948 [HIGH] CVE-2022-49948: In the Linux kernel, the following vulnerability has been resolved: vt: Clear selection before changing the font When changing the console font with i
In the Linux kernel, the following vulnerability has been resolved: vt: Clear selection before changing the font When changing the console font with ioctl(KDFONTOP) the new font size can be bigger than the previous font. A previous selection may thus now be outside of the new screen size and thus trigger out-of-bounds accesses to graphics memory if the selection is removed in vc_do_resize(). Prevent such out-of-memory accesses by dropping the selection before the various con_font_set() console handlers are called.
GHSA
GHSA-r6pw-rw8p-5cr9: In the Linux kernel, the following vulnerability has been resolved:
vt: Clear selection before changing the font
When changing the console font with
ghsa_unreviewed·2025-06-18
CVE-2022-49948 [HIGH] CWE-125 GHSA-r6pw-rw8p-5cr9: In the Linux kernel, the following vulnerability has been resolved:
vt: Clear selection before changing the font
When changing the console font with
In the Linux kernel, the following vulnerability has been resolved:
vt: Clear selection before changing the font
When changing the console font with ioctl(KDFONTOP) the new font size
can be bigger than the previous font. A previous selection may thus now
be outside of the new screen size and thus trigger out-of-bounds
accesses to graphics memory if the selection is removed in
vc_do_resize().
Prevent such out-of-memory accesses by dropping the selection before the
various con_font_set() console handlers are called.
Red Hat
kernel: vt: Clear selection before changing the font
vendor_redhat·2025-06-18·CVSS 7.1
CVE-2022-49948 [HIGH] kernel: vt: Clear selection before changing the font
kernel: vt: Clear selection before changing the font
In the Linux kernel, the following vulnerability has been resolved:
vt: Clear selection before changing the font
When changing the console font with ioctl(KDFONTOP) the new font size
can be bigger than the previous font. A previous selection may thus now
be outside of the new screen size and thus trigger out-of-bounds
accesses to graphics memory if the selection is removed in
vc_do_resize().
Prevent such out-of-memory accesses by dropping the selection before the
various con_font_set() console handlers are called.
Statement: Red Hat has stack protection mechanisms in place, such as FORTIFY_SOURCE, Position Independent Executables or Stack Smashing Protection.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kerne
Debian
CVE-2022-49948: linux - In the Linux kernel, the following vulnerability has been resolved: vt: Clear s...
vendor_debian·2022·CVSS 7.1
CVE-2022-49948 [HIGH] CVE-2022-49948: linux - In the Linux kernel, the following vulnerability has been resolved: vt: Clear s...
In the Linux kernel, the following vulnerability has been resolved: vt: Clear selection before changing the font When changing the console font with ioctl(KDFONTOP) the new font size can be bigger than the previous font. A previous selection may thus now be outside of the new screen size and thus trigger out-of-bounds accesses to graphics memory if the selection is removed in vc_do_resize(). Prevent such out-of-memory accesses by dropping the selection before the various con_font_set() console handlers are called.
Scope: local
bookworm: resolved (fixed in 6.0.2-1)
bullseye: resolved (fixed in 5.10.148-1)
forky: resolved (fixed in 6.0.2-1)
sid: resolved (fixed in 6.0.2-1)
trixie: resolved (fixed in 6.0.2-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/1cf1930369c9dc428d827b60260c53271bff3285https://git.kernel.org/stable/c/2535431ae967ad17585513649625fea7db28d4dbhttps://git.kernel.org/stable/c/566f9c9f89337792070b5a6062dff448b3e7977fhttps://git.kernel.org/stable/c/989201bb8c00b222235aff04e6200230d29dc7bbhttps://git.kernel.org/stable/c/c555cf04684fde39b5b0dd9fd80730030ee10c4ahttps://git.kernel.org/stable/c/c904fe03c4bd1f356a58797d39e2a5d0ca15cefchttps://git.kernel.org/stable/c/e9ba4611ddf676194385506222cce7b0844e708ehttps://git.kernel.org/stable/c/f74b4a41c5d7c9522469917e3072e55d435efd9e
2025-06-18
Published