Out-of-bounds write in Linux kernel - CVE-2026-46191
Published: May 29, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to out-of-bounds write in fbcon_rotate_font() and the rotated font buffer handling in fbcon when printing to a rotated console after console rotation reallocation fails. A local user can print a high-enough character code to overflow the font buffer to cause a denial of service.
Exploitation requires a console to be using rotation and the font reallocation during rotation to fail.
How to mitigate CVE-2026-46191
Sources
- https://git.kernel.org/stable/c/594973a2e54924d8ba31c9faac669fc1ba6fcb80
- https://git.kernel.org/stable/c/7105d9f1387d63b15c9a860674fc92c959181f2f
- https://git.kernel.org/stable/c/ab6c34b9829d5de03f1d08a47a2253729a6e7e27
- https://git.kernel.org/stable/c/b44cc78ff46b96e72d333a3be6aaaa0a14797263
- https://git.kernel.org/stable/c/e4ef723d8975a2694cc90733a6b888a5e2841842