kernel: fbcon: shift-out-of-bounds in fbcon_set_font()
Published Jun 12, 2023
5.5
MEDIUMCVSS 3.1
EPSS 0.20%
Description
A flaw was found in the Framebuffer Console (fbcon) in the Linux Kernel. When providing font->width and font->height greater than 32 to fbcon_set_font, since there are no checks in place, a shift-out-of-bounds occurs leading to undefined behavior and possible denial of service.
Affected products
- Vendor n/a Product Linux Kernel (fbcon) Defaultn/a
- Version Fixed in kernel 6.2-rc7StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Linux Kernel (fbcon) | n/a |
|
Configuration 1
- < 6.2
- 6.2
- 6.2
- 6.2
- 6.2
- 6.2
- 6.2
Configuration 2
- 38
Configuration 3
- 8.0
- 9.0
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-513.5.1.el8_9
Fixed · RHSA-2023:7077
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-513.5.1.rt7.307.el8_9
Fixed · RHSA-2023:6901
Red Hat Enterprise Linux 8.6 Extended Update Support
kernel-0:4.18.0-372.87.1.el8_6
Fixed · RHSA-2024:0412
Red Hat Enterprise Linux 9
kernel-0:5.14.0-362.8.1.el9_3
Fixed · RHSA-2023:6583
Red Hat Enterprise Linux 9
kernel-0:5.14.0-362.8.1.el9_3
Fixed · RHSA-2023:6583
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-0:5.14.0-70.75.1.el9_0
Fixed · RHSA-2023:5604
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-rt-0:5.14.0-70.75.1.rt21.146.el9_0
Fixed · RHSA-2023:5603
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
kernel-0:4.18.0-372.87.1.el8_6
Fixed · RHSA-2024:0412
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-513.5.1.el8_9 | Fixed | RHSA-2023:7077 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-513.5.1.rt7.307.el8_9 | Fixed | RHSA-2023:6901 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kernel-0:4.18.0-372.87.1.el8_6 | Fixed | RHSA-2024:0412 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-362.8.1.el9_3 | Fixed | RHSA-2023:6583 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-362.8.1.el9_3 | Fixed | RHSA-2023:6583 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-0:5.14.0-70.75.1.el9_0 | Fixed | RHSA-2023:5604 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-rt-0:5.14.0-70.75.1.rt21.146.el9_0 | Fixed | RHSA-2023:5603 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.87.1.el8_6 | Fixed | RHSA-2024:0412 |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://access.redhat.com/security/cve/CVE-2023-3161 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2213485 Issue TrackingPatchThird Party Advisory
- https://github.com/torvalds/linux/commit/2b09d5d364986f724f17001ccfe4126b9b43a0be Patch
- https://nvd.nist.gov/vuln/detail/CVE-2023-3161
- https://www.cve.org/CVERecord?id=CVE-2023-3161
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2023-3161 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2213485 | Issue TrackingPatchThird Party Advisory | |
| https://github.com/torvalds/linux/commit/2b09d5d364986f724f17001ccfe4126b9b43a0be | Patch | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-3161 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-3161 |
Change history (0)
No recorded changes yet.