CVE-2025-68296
Last modified
CVE-2025-68296 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup Protect vga_switcheroo_client_fb_set() with console lock. Avoids OOB access in fbcon_remap_all(). EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup Protect vga_switcheroo_client_fb_set() with console lock. Avoids OOB access in fbcon_remap_all(). Without holding the console lock the call races with switching outputs. VGA switcheroo calls fbcon_remap_all() when switching clients. The fbcon function uses struct fb_info.node, which is set by register_framebuffer(). As the fb-helper code currently sets up VGA switcheroo before registering the framebuffer, the value of node is -1 and therefore not a legal value. For example, fbcon uses the value within set_con2fb_map() [1] as an index into an array. Moving vga_switcheroo_client_fb_set() after register_framebuffer() can result in VGA switching that does not switch fbcon correctly. Therefore move vga_switcheroo_client_fb_set() under fbcon_fb_registered(), which already holds the console lock. Fbdev calls fbcon_fb_registered() from within register_framebuffer(). Serializes the helper with VGA switcheroo's call to fbcon_remap_all(). Although vga_switcheroo_client_fb_set() takes an instance of struct fb_info as parameter, it really only needs the contained fbcon state. Moving the call to fbcon initialization is therefore cleaner than before. Only amdgpu, i915, nouveau and radeon support vga_switcheroo. For all other drivers, this change does nothing.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 6a9ee8af344e3bd7dbd61e67037096cdf7f83289, < 711ebd961190def4c69ea24b2f0be75e995af24a; >= 6a9ee8af344e3bd7dbd61e67037096cdf7f83289, < 482330f8261b4bea8146d9bd69c1199e5dfcbb5c; >= 6a9ee8af344e3bd7dbd61e67037096cdf7f83289, < 05814c389b53d2f3a0b9eeb90ba7a05ba77c4c2a; >= 6a9ee8af344e3bd7dbd61e67037096cdf7f83289, < eb76d0f5553575599561010f24c277cc5b31d003 |
| Linux | Linux | 2.6.34 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-68296?
How severe is CVE-2025-68296?
How do I fix CVE-2025-68296?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-68290In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68291In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68292In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68293In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68294In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-68295In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68297In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68298In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68299In the Linux kernel, the following vulnerability has been re…
- CVE-2025-6830Improper Neutralization of Special Elements used in an SQL C…9.8
- CVE-2025-68300In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68301In the Linux kernel, the following vulnerability has been re…9.8
Are you affected by CVE-2025-68296?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
