AZL-27671

    Dashboard / Vulnerabilities / AZL-27671

    AZL-27671

    Published: 17 Jul 2023Last Modified: 21 Apr 2026
    Upstream:

    Summary: CVE-2023-38409 affecting package hyperv-daemons for versions less than 5.15.122.1-1

    Details: An issue was discovered in set_con2fb_map in drivers/video/fbdev/core/fbcon.c in the Linux kernel before 6.2.12. Because an assignment occurs only for the first vc, the fbcon_registered_fb and fbcon_display arrays can be desynchronized in fbcon_mode_deleted (the con2fb_map points at the old fb_info).

    Affected packages

    Package

    Name: hyperv-daemons

    Purl: pkg:rpm/azure-linux/hyperv-daemons

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -5.15.122.1-1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    AZL-27671 | CVE-DB