NULL pointer dereference in Linux kernel - CVE-2026-53403
Published: July 21, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in fb_videomode_to_var in the fbdev subsystem when processing a userspace-supplied modelist that does not contain the current framebuffer mode. A local user can supply a crafted mode list to trigger a kernel crash and cause a denial of service.
Exploitation requires fbcon to be unbound so that the current mode is left without a matching entry before a later console takeover occurs.
Affected software
How to mitigate CVE-2026-53403
External References
- https://git.kernel.org/stable/c/0d8c7f21ad8529d5c181e61f86be35b887ae2e4d
- https://git.kernel.org/stable/c/1458a4d804550b7101e8bb02c1cb941088e4c0c7
- https://git.kernel.org/stable/c/4f1a7fe8ba845cb7d39580755f78c3b7b9a0b61e
- https://git.kernel.org/stable/c/7640b4f68acb54c2c4f6b4a8aee0e9849dacd929
- https://git.kernel.org/stable/c/7f08fc10fa3d3366dc3af723970bd03d7d6d10e3
- https://git.kernel.org/stable/c/8707f02ac9f5f632039b60df2c9f3dc914709f72
- https://git.kernel.org/stable/c/88913059c77e171f44ba829282d42dde0d458811
- https://git.kernel.org/stable/c/eea16b6f805c0b1fb2f72f0f771088ea45356956