CVE-2023-38409Race Condition in Kernel

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 99.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 17
Latest updateAug 8

Description

An issue was discovered in set_con2fb_map in drivers/video/fbdev/core/fbcon.c in the Linux kernel before 6.2.12. Because an assignment occurs only for the first vc, the fbcon_registered_fb and fbcon_display arrays can be desynchronized in fbcon_mode_deleted (the con2fb_map points at the old fb_info).

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages10 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-jrp6-94m7-j7gw: An issue was discovered in set_con2fb_map in drivers/video/fbdev/core/fbcon2023-07-18
OSV
CVE-2023-38409: An issue was discovered in set_con2fb_map in drivers/video/fbdev/core/fbcon2023-07-17

📋Vendor Advisories

3
Microsoft
An issue was discovered in set_con2fb_map in drivers/video/fbdev/core/fbcon.c in the Linux kernel before 6.2.12. Because an assignment occurs only for the first vc the fbcon_registered_fb and fbcon_di2023-07-11
Red Hat
kernel: fbcon: out-of-sync arrays in fbcon_mode_deleted due to wrong con2fb_map assignment2023-04-12
Debian
CVE-2023-38409: linux - An issue was discovered in set_con2fb_map in drivers/video/fbdev/core/fbcon.c in...2023

💬Community

1
Bugzilla
CVE-2023-38409 kernel: fbcon: out-of-sync arrays in fbcon_mode_deleted due to wrong con2fb_map assignment2023-08-08
CVE-2023-38409 — Race Condition in Linux Kernel | cvebase