In the Linux kernel, the following vulnerability has been resolved:
fbdev: bound mode sysfs output to the sysfs buffer
mode_string() uses snprintf() which can return a value larger than the
remaining buffer space. show_modes() accumulates the return value into i
without checking whether i has reached PAGE_SIZE, causing the offset to
advance past the sysfs buffer if the modelist is long enough.
Add a size parameter to mode_string() and use scnprintf() to return
only the bytes actually written. Add an early return when offset
already exceeds the buffer. In show_modes(), stop accumulating once
the buffer is full.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-26 15:17
Updated : 2026-08-27 06:17
NVD link : CVE-2026-80580
Mitre link : CVE-2026-80580
CVE.ORG link : CVE-2026-80580
JSON object : View
Products Affected
No product.
CWE
No CWE.
