Answer in brief
CVE-2025-68296 records a Unknown severity vulnerability in drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=6a9ee8af344e3bd7dbd61e67037096cdf7f83289 <711ebd961190def4c69ea24b2f0be75e995af24a || >=6a9ee8af344e3bd7dbd61e67037096cdf7f83289 <482330f8261b4bea8146d9bd69c1199e5dfcbb5c || >=6a9ee8af344e3bd7dbd61e67037096cdf7f83289 <05814c389b53d2f3a0b9eeb90ba7a05ba77c4c2a || >=6a9ee8af344e3bd7dbd61e67037096cdf7f83289 <eb76d0f5553575599561010f24c277cc5b31d003 | 711ebd961190def4c69ea24b2f0be75e995af24a, 482330f8261b4bea8146d9bd69c1199e5dfcbb5c, 05814c389b53d2f3a0b9eeb90ba7a05ba77c4c2a, eb76d0f5553575599561010f24c277cc5b31d003 |
| Linux/Linuxgeneric | 2.6.34 | Not reported |
Published upstream
Dec 16, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jun 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jun 19, 2026
In the Linux kernel, the following vulnerability has been resolved: drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup Protect vga_switcheroo_client_fb_set() with console lock. Avoids OOB access in fbcon_remap_all(). Without holding the console lock the call races with switching outputs. VGA switcheroo calls fbcon_remap_all() when switching clients. The fbcon function uses struct fb_info.node, which is set by register_framebuffer(). As the fb-helper code currently sets up VGA switcheroo before registering the framebuffer, the value of node is -1 and therefore not a legal value. For example, fbcon uses the value within set_con2fb_map() [1] as an index into an array. Moving vga_switcheroo_client_fb_set() after register_framebuffer() can result in VGA switching that does not switch fbcon correctly. Therefore move vga_switcheroo_client_fb_set() under fbcon_fb_registered(), which already holds the console lock. Fbdev calls fbcon_fb_registered() from within register_framebuffer(). Serializes the helper with VGA switcheroo's call to fbcon_remap_all(). Although vga_switcheroo_client_fb_set() takes an instance of struct fb_info as parameter, it really only needs the contained fbcon state. Moving the call to fbcon initialization is therefore cleaner than before. Only amdgpu, i915, nouveau and radeon support vga_switcheroo. For all other drivers, this change does nothing.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2025-68296 records a Unknown severity vulnerability in drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=6a9ee8af344e3bd7dbd61e67037096cdf7f83289 <711ebd961190def4c69ea24b2f0be75e995af24a || >=6a9ee8af344e3bd7dbd61e67037096cdf7f83289 <482330f8261b4bea8146d9bd69c1199e5dfcbb5c || >=6a9ee8af344e3bd7dbd61e67037096cdf7f83289 <05814c389b53d2f3a0b9eeb90ba7a05ba77c4c2a || >=6a9ee8af344e3bd7dbd61e67037096cdf7f83289 <eb76d0f5553575599561010f24c277cc5b31d003 | 711ebd961190def4c69ea24b2f0be75e995af24a, 482330f8261b4bea8146d9bd69c1199e5dfcbb5c, 05814c389b53d2f3a0b9eeb90ba7a05ba77c4c2a, eb76d0f5553575599561010f24c277cc5b31d003 |
| Linux/Linuxgeneric | 2.6.34 | Not reported |
Published upstream
Dec 16, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jun 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jun 19, 2026
In the Linux kernel, the following vulnerability has been resolved: drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup Protect vga_switcheroo_client_fb_set() with console lock. Avoids OOB access in fbcon_remap_all(). Without holding the console lock the call races with switching outputs. VGA switcheroo calls fbcon_remap_all() when switching clients. The fbcon function uses struct fb_info.node, which is set by register_framebuffer(). As the fb-helper code currently sets up VGA switcheroo before registering the framebuffer, the value of node is -1 and therefore not a legal value. For example, fbcon uses the value within set_con2fb_map() [1] as an index into an array. Moving vga_switcheroo_client_fb_set() after register_framebuffer() can result in VGA switching that does not switch fbcon correctly. Therefore move vga_switcheroo_client_fb_set() under fbcon_fb_registered(), which already holds the console lock. Fbdev calls fbcon_fb_registered() from within register_framebuffer(). Serializes the helper with VGA switcheroo's call to fbcon_remap_all(). Although vga_switcheroo_client_fb_set() takes an instance of struct fb_info as parameter, it really only needs the contained fbcon state. Moving the call to fbcon initialization is therefore cleaner than before. Only amdgpu, i915, nouveau and radeon support vga_switcheroo. For all other drivers, this change does nothing.
Quoted source text, attributed separately from HOL analysis.