CVE-2026-80786

    Dashboard / Vulnerabilities / CVE-2026-80786

    CVE-2026-80786

    Published: 4 Sept 2026Last Modified: 9 Sept 2026

    Summary: fbdev: Wrap user-invoked calls to fb_set_var() in helper

    Details: In the Linux kernel, the following vulnerability has been resolved: fbdev: Wrap user-invoked calls to fb_set_var() in helper Handle fbcon during display updates in fb_set_var_from_user(). Check with fbcon if the mode change is possible, update hardware state and finally update fbcon. Update all callers. Only the FBIOPUT_VSCREENINFO ioctl currently does all steps. Other mode-changes callers in sysfs and driver code are missing fbcon-related steps. With the new helper, ps3fb and sh_mobile_lcdcfb no longer maintain fbcon state themselves.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2

    Affected versions

    v7.1.10
    v7.1.9
    v7.1.8
    v7.1.7
    v7.1.6
    v7.1.5
    v7.1.4
    v7.1.3
    v7.1.2
    v7.1.1
    v7.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2026-80786 | CVE-DB