UBUNTU-CVE-2026-80786
Dashboard / Vulnerabilities / UBUNTU-CVE-2026-80786
Summary:
Details: In the Linux kernel, the following vulnerability has been resolved: fbdev: Wrap user-invoked calls to fb_set_var() in helper Handle fbcon during display updates in fb_set_var_from_user(). Check with fbcon if the mode change is possible, update hardware state and finally update fbcon. Update all callers. Only the FBIOPUT_VSCREENINFO ioctl currently does all steps. Other mode-changes callers in sysfs and driver code are missing fbcon-related steps. With the new helper, ps3fb and sh_mobile_lcdcfb no longer maintain fbcon state themselves.
References: https://ubuntu.com/security/CVE-2026-80786, https://www.cve.org/CVERecord?id=CVE-2026-80786, https://git.kernel.org/linus/6f611e5e5f3327cf2e2daabe6ee5acac58cc784e
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
