Vulnerability Description
A flaw was found in the Framebuffer Console (fbcon) in the Linux Kernel. When providing font->width and font->height greater than 32 to fbcon_set_font, since there are no checks in place, a shift-out-of-bounds occurs leading to undefined behavior and possible denial of service.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 6.2 |
| Fedoraproject | Fedora | 38 |
| Redhat | Enterprise Linux | 8.0 |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2213485Issue TrackingPatchThird Party Advisory
- https://github.com/torvalds/linux/commit/2b09d5d364986f724f17001ccfe4126b9b43a0bPatch
- https://bugzilla.redhat.com/show_bug.cgi?id=2213485Issue TrackingPatchThird Party Advisory
- https://github.com/torvalds/linux/commit/2b09d5d364986f724f17001ccfe4126b9b43a0bPatch
FAQ
What is CVE-2023-3161?
CVE-2023-3161 is a vulnerability with a CVSS score of 5.5 (MEDIUM). A flaw was found in the Framebuffer Console (fbcon) in the Linux Kernel. When providing font->width and font->height greater than 32 to fbcon_set_font, since there are no checks in place, a shift-out-...
How severe is CVE-2023-3161?
CVE-2023-3161 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-3161?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Fedoraproject Fedora, Redhat Enterprise Linux.