Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-38409
HistoryJul 17, 2023 - 12:00 a.m.

CVE-2023-38409

2023-07-1700:00:00
ubuntu.com
ubuntu.com
9
set_con2fb_map
fbdev core
linux kernel 6.2.12

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

9.2%

An issue was discovered in set_con2fb_map in
drivers/video/fbdev/core/fbcon.c in the Linux kernel before 6.2.12. Because
an assignment occurs only for the first vc, the fbcon_registered_fb and
fbcon_display arrays can be desynchronized in fbcon_mode_deleted (the
con2fb_map points at the old fb_info).

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

9.2%