FlawAtlas
Search the atlas
CVE-2025-39967 Not scored

fbcon: fix integer overflow in fbcon_do_set_font

In the Linux kernel, the following vulnerability has been resolved: fbcon: fix integer overflow in fbcon_do_set_font Fix integer overflow vulnerabilities in fbcon_do_set_font() where font size calculations could overflow when handling user-controlled font parameters. The vulnerabilities occur when: 1. CALC_FONTSZ(h, pitch, charcount) performs h * pith * charcount multiplication with user-controlled values that can overflow. 2. FONT_EXTRA_WORDS * sizeof(int) + size addition can also overflow 3. This results in smaller allocations than expected, leading to buffer overflows during font data copying. Add explicit overflow checking using check_mul_overflow() and check_add_overflow() kernel helpers to safety validate all size calculations before allocation.

Exploit probability 0.2%
Published October 15, 2025
Required by Not available
Last source change July 15, 2026

02 / AFFECTED SOFTWARE

Affected packages

Linux Kernel
Unknown Unknown

1690 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2025:20091-1
related SUSE-SU-2025:21040-1
related SUSE-SU-2025:21052-1
related SUSE-SU-2025:21056-1
related SUSE-SU-2025:21064-1
related SUSE-SU-2025:21080-1
related SUSE-SU-2025:21147-1
related SUSE-SU-2025:21180-1
related SUSE-SU-2025:4057-1
related SUSE-SU-2025:4111-1
related SUSE-SU-2025:4128-1
related SUSE-SU-2025:4132-1
related SUSE-SU-2025:4139-1
related SUSE-SU-2025:4140-1
related SUSE-SU-2025:4141-1
related SUSE-SU-2025:4149-1
related SUSE-SU-2025:4301-1
related SUSE-SU-2025:4320-1
related SUSE-SU-2025:4515-1
related SUSE-SU-2026:0029-1
related SUSE-SU-2026:0033-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2025-39967

In the Linux kernel, the following vulnerability has been resolved: fbcon: fix integer overflow in fbcon_do_set_font Fix integer overflow vulnerabilities in fbcon_do_set_font() where font size calculations could overflow when handling user-controlled font parameters. The vulnerabilities occur when: 1. CALC_FONTSZ(h, pitch, charcount) performs h * pith * charcount multiplication with user-controlled values that can overflow. 2. FONT_EXTRA_WORDS * sizeof(int) + size addition can also overflow 3. This results in smaller allocations than expected, leading to buffer overflows during font data copying. Add explicit overflow checking using check_mul_overflow() and check_add_overflow() kernel helpers to safety validate all size calculations before allocation.

View original source

05 / REFERENCES

Further evidence