fbdev: fbcon: release buffer when fbcon_do_set_font() failed
CVE-2022-50404

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
18 September 2025

What is CVE-2022-50404?

In the Linux kernel, the following vulnerability has been resolved:

fbdev: fbcon: release buffer when fbcon_do_set_font() failed

syzbot is reporting memory leak at fbcon_do_set_font() [1], for commit a5a923038d70 ("fbdev: fbcon: Properly revert changes when vc_resize() failed") missed that the buffer might be newly allocated by fbcon_set_font().

Affected Version(s)

Linux ebd6f886aa2447fcfcdce5450c9e1028e1d681bb < 88ec6d11052da527eb9268831e7a9bc5bbad02f6

Linux a5a923038d70d2d4a86cb4e3f32625a5ee6e7e24 < 06926607b9fddf7ce8017493899ce6eb7e79a123

Linux a5a923038d70d2d4a86cb4e3f32625a5ee6e7e24

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2022-50404 : Linux Kernel Memory Leak Vulnerability in fbdev Component