Answer in brief
CVE-2026-74424 records a Unknown severity vulnerability in fbcon: fix NULL pointer dereference for a console without vc_data. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-74424 records a Unknown severity vulnerability in fbcon: fix NULL pointer dereference for a console without vc_data. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <8e9b8b008f4036df0318870c5d754134ff1b94cc || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <cc4382dc5134826a3936a6b08de17f7dc7abe232 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <9b783b7e03dc78ec102edf618259a2b55911fc6a || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <ac970358c5ca0775841bd2a56ce15dc464b99003 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <6617df8c246311c82cebf061a4cee55b9df60922 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <b134ad2f7c06b3c1098dcc95008e2045ff4b49b2 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <5fae9a928482d4845bca169a3a098789203a1ca4 || >=0 <5.15.212 || >=0 <6.1.178 || >=0 <6.6.145 || >=0 <6.12.97 || >=0 <6.18.40 || >=0 <7.1.5 | 8e9b8b008f4036df0318870c5d754134ff1b94cc, cc4382dc5134826a3936a6b08de17f7dc7abe232, 9b783b7e03dc78ec102edf618259a2b55911fc6a, ac970358c5ca0775841bd2a56ce15dc464b99003, 6617df8c246311c82cebf061a4cee55b9df60922, b134ad2f7c06b3c1098dcc95008e2045ff4b49b2, 5fae9a928482d4845bca169a3a098789203a1ca4, 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, 7.1.5 |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: fbcon: fix NULL pointer dereference for a console without vc_data fbcon_new_modelist() runs when a framebuffer's modelist changes. For each console mapped to it with fb_display[i].mode set, it reads vc_cons[i].d and passes the vc_num to fbcon_set_disp(). This assumes a console with a mode set has a vc_data, but it can be NULL. fbcon_set_disp() sets fb_display[i].mode before it checks vc_data, and fbcon_deinit() leaves the mode set after the vc_data is freed. fbcon_new_modelist() then dereferences the NULL vc_data. Keep fb_display[i].mode set only while the console has a vc_data. Check vc_data before setting the mode in fbcon_set_disp(), and clear the mode in fbcon_deinit(). The existing mode check in fbcon_new_modelist() then skips such consoles.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <8e9b8b008f4036df0318870c5d754134ff1b94cc || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <cc4382dc5134826a3936a6b08de17f7dc7abe232 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <9b783b7e03dc78ec102edf618259a2b55911fc6a || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <ac970358c5ca0775841bd2a56ce15dc464b99003 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <6617df8c246311c82cebf061a4cee55b9df60922 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <b134ad2f7c06b3c1098dcc95008e2045ff4b49b2 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <5fae9a928482d4845bca169a3a098789203a1ca4 || >=0 <5.15.212 || >=0 <6.1.178 || >=0 <6.6.145 || >=0 <6.12.97 || >=0 <6.18.40 || >=0 <7.1.5 | 8e9b8b008f4036df0318870c5d754134ff1b94cc, cc4382dc5134826a3936a6b08de17f7dc7abe232, 9b783b7e03dc78ec102edf618259a2b55911fc6a, ac970358c5ca0775841bd2a56ce15dc464b99003, 6617df8c246311c82cebf061a4cee55b9df60922, b134ad2f7c06b3c1098dcc95008e2045ff4b49b2, 5fae9a928482d4845bca169a3a098789203a1ca4, 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, 7.1.5 |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: fbcon: fix NULL pointer dereference for a console without vc_data fbcon_new_modelist() runs when a framebuffer's modelist changes. For each console mapped to it with fb_display[i].mode set, it reads vc_cons[i].d and passes the vc_num to fbcon_set_disp(). This assumes a console with a mode set has a vc_data, but it can be NULL. fbcon_set_disp() sets fb_display[i].mode before it checks vc_data, and fbcon_deinit() leaves the mode set after the vc_data is freed. fbcon_new_modelist() then dereferences the NULL vc_data. Keep fb_display[i].mode set only while the console has a vc_data. Check vc_data before setting the mode in fbcon_set_disp(), and clear the mode in fbcon_deinit(). The existing mode check in fbcon_new_modelist() then skips such consoles.
Quoted source text, attributed separately from HOL analysis.