cbcvebase.
CVE-2025-39967
published 2025-10-15

CVE-2025-39967: In the Linux kernel, the following vulnerability has been resolved: fbcon: fix integer overflow in fbcon_do_set_font Fix integer overflow vulnerabilities in…

PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.16%
5.5th percentile
In the Linux kernel, the following vulnerability has been resolved: fbcon: fix integer overflow in fbcon_do_set_font Fix integer overflow vulnerabilities in fbcon_do_set_font() where font size calculations could overflow when handling user-controlled font parameters. The vulnerabilities occur when: 1. CALC_FONTSZ(h, pitch, charcount) performs h * pith * charcount multiplication with user-controlled values that can overflow. 2. FONT_EXTRA_WORDS * sizeof(int) + size addition can also overflow 3. This results in smaller allocations than expected, leading to buffer overflows during font data copying. Add explicit overflow checking using check_mul_overflow() and check_add_overflow() kernel helpers to safety validate all size calculations before allocation.

Affected

48 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 39b3cffb8cf3111738ea993e2757ab382253d86a < 9c8ec14075c5317edd6b242f1be8167aa1e4e3339c8ec14075c5317edd6b242f1be8167aa1e4e333
linuxlinux>= 39b3cffb8cf3111738ea993e2757ab382253d86a < b8a6e85328aeb9881531dbe89bcd2637a06c3c95b8a6e85328aeb9881531dbe89bcd2637a06c3c95
linuxlinux>= 39b3cffb8cf3111738ea993e2757ab382253d86a < a6eb9f423b3db000aaedf83367b8539f6b72dcfca6eb9f423b3db000aaedf83367b8539f6b72dcfc
linuxlinux>= 39b3cffb8cf3111738ea993e2757ab382253d86a < adac90bb1aaf45ca66f9db8ac100be16750ace78adac90bb1aaf45ca66f9db8ac100be16750ace78
linuxlinux>= 39b3cffb8cf3111738ea993e2757ab382253d86a < 4a4bac869560f943edbe3c2b032062f6673b13d34a4bac869560f943edbe3c2b032062f6673b13d3
linuxlinux>= 39b3cffb8cf3111738ea993e2757ab382253d86a < c0c01f9aa08c8e10e10e8c9ebb5be01a4eff6eb7c0c01f9aa08c8e10e10e8c9ebb5be01a4eff6eb7
linuxlinux>= 39b3cffb8cf3111738ea993e2757ab382253d86a < 1a194e6c8e1ee745e914b0b7f50fa86c89ed13fe1a194e6c8e1ee745e914b0b7f50fa86c89ed13fe
linuxlinux>= 4.14.196 < 4.154.15
linuxlinux>= 4.19.143 < 4.204.20
linuxlinux>= 4.4.235 < 4.54.5
linuxlinux>= 4.9.235 < 4.104.10
linuxlinux>= 5.4.62 < 5.4.3005.4.300
linuxlinux>= 5.8.6 < 5.95.9
linuxlinux>= 96e41fc29e8af5c5085fb8a79cab8d0d00bab86c < 994bdc2d23c79087fbf7dcd9544454e8ebcef877994bdc2d23c79087fbf7dcd9544454e8ebcef877
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_msrc9.8CRITICAL
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.