Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.8
CVE-2025-39967: Linux Kernel Font Size Calculation Error
CVE-2025-39967 · published 10 months ago
Summary
A bug in the Linux kernel's font handling could cause the system to incorrectly calculate font sizes, potentially leading to data corruption or crashes. This vulnerability has been fixed in a recent update, and users should apply the patch to ensure their system's font handling is secure. Admins should update their Linux kernel to the latest version to prevent potential issues.
What to do
- Update linux linux to version 994bdc2d23c79087fbf7dcd9544454e8ebcef877 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| linux | linux_kernel |
>= 4.4.235, < 4.5 >= 4.9.235, < 4.10 >= 4.14.196, < 4.15 >= 4.19.143, < 4.20 >= 5.4.62, < 5.4.300 >= 5.8.6, < 5.9 >= 5.9.1, < 5.10.245 >= 5.11, < 5.15.194 >= 5.16, < 6.1.155 >= 6.2, < 6.6.109 >= 6.7, < 6.12.50 >= 6.13, < 6.16.10 5.9 6.17 cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| linux | linux |
< 994bdc2d23c79087fbf7dcd9544454e8ebcef877 5.9 |
Original advisory text
fbcon: fix integer overflow in fbcon_do_set_font
In the Linux kernel, the following vulnerability has been resolved:
fbcon: fix integer overflow in fbcon_do_set_font
Fix integer overflow vulnerabilities in fbcon_do_set_font() where font
size calculations could overflow when handling user-controlled font
parameters.
The vulnerabilities occur when:
1. CALC_FONTSZ(h, pitch, charcount) performs h * pith * charcount
multiplication with user-controlled values that can overflow.
2. FONT_EXTRA_WORDS * sizeof(int) + size addition can also overflow
3. This results in smaller allocations than expected, leading to buffer
overflows during font data copying.
Add explicit overflow checking using check_mul_overflow() and
check_add_overflow() kernel helpers to safety validate all size
calculations before allocation.
fbcon: fix integer overflow in fbcon_do_set_font
Fix integer overflow vulnerabilities in fbcon_do_set_font() where font
size calculations could overflow when handling user-controlled font
parameters.
The vulnerabilities occur when:
1. CALC_FONTSZ(h, pitch, charcount) performs h * pith * charcount
multiplication with user-controlled values that can overflow.
2. FONT_EXTRA_WORDS * sizeof(int) + size addition can also overflow
3. This results in smaller allocations than expected, leading to buffer
overflows during font data copying.
Add explicit overflow checking using check_mul_overflow() and
check_add_overflow() kernel helpers to safety validate all size
calculations before allocation.
References
- https://git.kernel.org/stable/c/1a194e6c8e1ee745e914b0b7f50fa86c89ed13fe Patch
- https://git.kernel.org/stable/c/4a4bac869560f943edbe3c2b032062f6673b13d3 Patch
- https://git.kernel.org/stable/c/994bdc2d23c79087fbf7dcd9544454e8ebcef877 Patch
- https://git.kernel.org/stable/c/9c8ec14075c5317edd6b242f1be8167aa1e4e333 Patch
- https://git.kernel.org/stable/c/a6eb9f423b3db000aaedf83367b8539f6b72dcfc Patch
- https://git.kernel.org/stable/c/adac90bb1aaf45ca66f9db8ac100be16750ace78 Patch
- https://git.kernel.org/stable/c/b8a6e85328aeb9881531dbe89bcd2637a06c3c95 Patch
- https://git.kernel.org/stable/c/c0c01f9aa08c8e10e10e8c9ebb5be01a4eff6eb7 Patch
Severity
7.8
High
CVSS 3.1: 7.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-190Integer Overflow
Timeline
Published15 Oct 2025
Updated30 Jul 2026
First seen6 Mar 2026
Monitor software like this
Free during beta