auxdisplay: line-display: fix OOB read on zero-length message_store()
Summary
| CVE | CVE-2026-63949 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-19 16:17:13 UTC |
| Updated | 2026-07-27 17:44:23 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: auxdisplay: line-display: fix OOB read on zero-length message_store() linedisp_display() unconditionally reads msg[count - 1] before checking whether count is zero, so a write of zero bytes to the message sysfs attribute hits msg[-1]: write(fd, "", 0); -> message_store(..., buf, count=0) -> linedisp_display(linedisp, buf, count=0) -> msg[count - 1] == '\n' ; OOB read The kernfs write buffer for that store is a 1-byte allocation (kernfs_fop_write_iter() does kmalloc(len + 1) with len == 0), so msg[-1] is a 1-byte read before the slab object. On a KASAN-enabled kernel this trips an out-of-bounds report and panics; on stock kernels it silently reads adjacent slab data and, if that byte happens to be '\n', the following count-- wraps ssize_t 0 to -1 and is then passed to kmemdup_nul(). linedisp_display() is reached from the message_store() sysfs callback (drivers/auxdisplay/line-display.c message attribute, mode 0644) and from the in-tree initial-message setup with count == -1, so the OOB path is only userspace-triggerable via zero-byte writes; vfs_write() does not short-circuit on count == 0 and kernfs_fop_write_iter() dispatches the store callback regardless. Guard the trailing-newline trim with a count check. The existing if (!count) block then takes the clear-display path unchanged. Affects every auxdisplay driver that registers via linedisp_register() / linedisp_attach(): ht16k33, max6959, img-ascii-lcd, seg-led-gpio. |
Risk And Classification
EPSS: 0.001720000 probability, percentile 0.068950000 (date 2026-07-29)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 7e76aece6f036cb7ada4858d6aa73825bfe22983 ca5b0781946d5083ceafa752141f47f085853620 git | Not specified |
| CNA | Linux | Linux | affected 7e76aece6f036cb7ada4858d6aa73825bfe22983 8776032fe989a9b5fc77f2de5e03e4adb44c630e git | Not specified |
| CNA | Linux | Linux | affected 7e76aece6f036cb7ada4858d6aa73825bfe22983 3859960daeb9b7b39b9847b5b0113bc6081eb735 git | Not specified |
| CNA | Linux | Linux | affected 7e76aece6f036cb7ada4858d6aa73825bfe22983 197476b126010bac1b3199833c6966cd6f54c2a9 git | Not specified |
| CNA | Linux | Linux | affected 7e76aece6f036cb7ada4858d6aa73825bfe22983 6ad4f75ef9f3372fce8cad494e789ac6a5507bef git | Not specified |
| CNA | Linux | Linux | affected 7e76aece6f036cb7ada4858d6aa73825bfe22983 a7511dcd9dd4bc55d123f9b800c8a4ed2662e5c6 git | Not specified |
| CNA | Linux | Linux | affected 5.16 | Not specified |
| CNA | Linux | Linux | unaffected 5.16 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.176 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.143 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.93 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.35 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.0.12 7.0.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/197476b126010bac1b3199833c6966cd6f54c2a9 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/6ad4f75ef9f3372fce8cad494e789ac6a5507bef | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/a7511dcd9dd4bc55d123f9b800c8a4ed2662e5c6 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/ca5b0781946d5083ceafa752141f47f085853620 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/8776032fe989a9b5fc77f2de5e03e4adb44c630e | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/3859960daeb9b7b39b9847b5b0113bc6081eb735 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.