Out-of-bounds read in Linux kernel - CVE-2026-63949
Published: July 20, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in linedisp_display() in the line-display auxdisplay subsystem when handling a zero-byte write to the message sysfs attribute. A local user can write zero bytes to the message sysfs attribute to cause a denial of service.
On KASAN-enabled kernels, the issue triggers an out-of-bounds report and panic.
How to mitigate CVE-2026-63949
Sources
- https://git.kernel.org/stable/c/197476b126010bac1b3199833c6966cd6f54c2a9
- https://git.kernel.org/stable/c/3859960daeb9b7b39b9847b5b0113bc6081eb735
- https://git.kernel.org/stable/c/6ad4f75ef9f3372fce8cad494e789ac6a5507bef
- https://git.kernel.org/stable/c/8776032fe989a9b5fc77f2de5e03e4adb44c630e
- https://git.kernel.org/stable/c/a7511dcd9dd4bc55d123f9b800c8a4ed2662e5c6
- https://git.kernel.org/stable/c/ca5b0781946d5083ceafa752141f47f085853620