Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-74424

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
15/08/2026
Última modificación:
15/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> fbcon: fix NULL pointer dereference for a console without vc_data<br /> <br /> fbcon_new_modelist() runs when a framebuffer&amp;#39;s modelist changes. For each<br /> console mapped to it with fb_display[i].mode set, it reads vc_cons[i].d and<br /> passes the vc_num to fbcon_set_disp(). This assumes a console with a mode<br /> set has a vc_data, but it can be NULL. fbcon_set_disp() sets<br /> fb_display[i].mode before it checks vc_data, and fbcon_deinit() leaves the<br /> mode set after the vc_data is freed. fbcon_new_modelist() then dereferences<br /> the NULL vc_data.<br /> <br /> Keep fb_display[i].mode set only while the console has a vc_data. Check<br /> vc_data before setting the mode in fbcon_set_disp(), and clear the mode in<br /> fbcon_deinit(). The existing mode check in fbcon_new_modelist() then skips<br /> such consoles.

Impacto