Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
- >= 2.6.34, < 2.6.34.1
A race condition vulnerability has been addressed in the Linux kernel's handling of VGA switcheroo clients and the framebuffer console (fbcon). This issue arises because the VGA switcheroo helper is invoked before the framebuffer is fully registered, leading to an invalid state that can cause out-of-bounds access when fbcon attempts to remap all clients. The vulnerability affects the amdgpu, i915, nouveau, and radeon drivers, all of which support VGA switcheroo. The root cause is the improper timing of function calls related to framebuffer registration and VGA output switching, which can disrupt the expected behavior of the console framebuffer management.
Exploitation of this vulnerability could lead to incorrect handling of framebuffer console output when switching VGA clients, potentially causing graphical display issues or inconsistencies.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been addressed. Instructions for downloading the patched version are available on the Linux kernel official website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.