Answer in brief
CVE-2025-39967 records a Unknown severity vulnerability in fbcon: fix integer overflow in fbcon_do_set_font. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2025-39967 records a Unknown severity vulnerability in fbcon: fix integer overflow in fbcon_do_set_font. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | 5.9 | Not reported |
| Linux/Linuxgeneric | >=96e41fc29e8af5c5085fb8a79cab8d0d00bab86c <994bdc2d23c79087fbf7dcd9544454e8ebcef877 || >=39b3cffb8cf3111738ea993e2757ab382253d86a <9c8ec14075c5317edd6b242f1be8167aa1e4e333 || >=39b3cffb8cf3111738ea993e2757ab382253d86a <b8a6e85328aeb9881531dbe89bcd2637a06c3c95 || >=39b3cffb8cf3111738ea993e2757ab382253d86a <a6eb9f423b3db000aaedf83367b8539f6b72dcfc || >=39b3cffb8cf3111738ea993e2757ab382253d86a <adac90bb1aaf45ca66f9db8ac100be16750ace78 || >=39b3cffb8cf3111738ea993e2757ab382253d86a <4a4bac869560f943edbe3c2b032062f6673b13d3 || >=39b3cffb8cf3111738ea993e2757ab382253d86a <c0c01f9aa08c8e10e10e8c9ebb5be01a4eff6eb7 || >=39b3cffb8cf3111738ea993e2757ab382253d86a <1a194e6c8e1ee745e914b0b7f50fa86c89ed13fe || ae021a904ac82d9fc81c25329d3c465c5a7d5686 || 451bffa366f2cc0e5314807cb847f31c0226efed || 2c455e9c5865861f5ce09c5f596909495ed7657c || 72f099805dbc907fbe8fa19bccdc31d3e2ee6e9e || 34cf1aff169dc6dedad8d79da7bf1b4de2773dbc || >=5.4.62 <5.4.300 || >=4.4.235 <4.5 || >=4.9.235 <4.10 || >=4.14.196 <4.15 || >=4.19.143 <4.20 || >=5.8.6 <5.9 | 994bdc2d23c79087fbf7dcd9544454e8ebcef877, 9c8ec14075c5317edd6b242f1be8167aa1e4e333, b8a6e85328aeb9881531dbe89bcd2637a06c3c95, a6eb9f423b3db000aaedf83367b8539f6b72dcfc, adac90bb1aaf45ca66f9db8ac100be16750ace78, 4a4bac869560f943edbe3c2b032062f6673b13d3, c0c01f9aa08c8e10e10e8c9ebb5be01a4eff6eb7, 1a194e6c8e1ee745e914b0b7f50fa86c89ed13fe, 5.4.300, 4.5, 4.10, 4.15, 4.20, 5.9 |
Published upstream
Oct 15, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: fbcon: fix integer overflow in fbcon_do_set_font Fix integer overflow vulnerabilities in fbcon_do_set_font() where font size calculations could overflow when handling user-controlled font parameters. The vulnerabilities occur when: 1. CALC_FONTSZ(h, pitch, charcount) performs h * pith * charcount multiplication with user-controlled values that can overflow. 2. FONT_EXTRA_WORDS * sizeof(int) + size addition can also overflow 3. This results in smaller allocations than expected, leading to buffer overflows during font data copying. Add explicit overflow checking using check_mul_overflow() and check_add_overflow() kernel helpers to safety validate all size calculations before allocation.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | 5.9 | Not reported |
| Linux/Linuxgeneric | >=96e41fc29e8af5c5085fb8a79cab8d0d00bab86c <994bdc2d23c79087fbf7dcd9544454e8ebcef877 || >=39b3cffb8cf3111738ea993e2757ab382253d86a <9c8ec14075c5317edd6b242f1be8167aa1e4e333 || >=39b3cffb8cf3111738ea993e2757ab382253d86a <b8a6e85328aeb9881531dbe89bcd2637a06c3c95 || >=39b3cffb8cf3111738ea993e2757ab382253d86a <a6eb9f423b3db000aaedf83367b8539f6b72dcfc || >=39b3cffb8cf3111738ea993e2757ab382253d86a <adac90bb1aaf45ca66f9db8ac100be16750ace78 || >=39b3cffb8cf3111738ea993e2757ab382253d86a <4a4bac869560f943edbe3c2b032062f6673b13d3 || >=39b3cffb8cf3111738ea993e2757ab382253d86a <c0c01f9aa08c8e10e10e8c9ebb5be01a4eff6eb7 || >=39b3cffb8cf3111738ea993e2757ab382253d86a <1a194e6c8e1ee745e914b0b7f50fa86c89ed13fe || ae021a904ac82d9fc81c25329d3c465c5a7d5686 || 451bffa366f2cc0e5314807cb847f31c0226efed || 2c455e9c5865861f5ce09c5f596909495ed7657c || 72f099805dbc907fbe8fa19bccdc31d3e2ee6e9e || 34cf1aff169dc6dedad8d79da7bf1b4de2773dbc || >=5.4.62 <5.4.300 || >=4.4.235 <4.5 || >=4.9.235 <4.10 || >=4.14.196 <4.15 || >=4.19.143 <4.20 || >=5.8.6 <5.9 | 994bdc2d23c79087fbf7dcd9544454e8ebcef877, 9c8ec14075c5317edd6b242f1be8167aa1e4e333, b8a6e85328aeb9881531dbe89bcd2637a06c3c95, a6eb9f423b3db000aaedf83367b8539f6b72dcfc, adac90bb1aaf45ca66f9db8ac100be16750ace78, 4a4bac869560f943edbe3c2b032062f6673b13d3, c0c01f9aa08c8e10e10e8c9ebb5be01a4eff6eb7, 1a194e6c8e1ee745e914b0b7f50fa86c89ed13fe, 5.4.300, 4.5, 4.10, 4.15, 4.20, 5.9 |
Published upstream
Oct 15, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: fbcon: fix integer overflow in fbcon_do_set_font Fix integer overflow vulnerabilities in fbcon_do_set_font() where font size calculations could overflow when handling user-controlled font parameters. The vulnerabilities occur when: 1. CALC_FONTSZ(h, pitch, charcount) performs h * pith * charcount multiplication with user-controlled values that can overflow. 2. FONT_EXTRA_WORDS * sizeof(int) + size addition can also overflow 3. This results in smaller allocations than expected, leading to buffer overflows during font data copying. Add explicit overflow checking using check_mul_overflow() and check_add_overflow() kernel helpers to safety validate all size calculations before allocation.
Quoted source text, attributed separately from HOL analysis.