In the Linux kernel, the following vulnerability has been resolved:
lib/fonts: fix undefined behavior in bit shift for get_default_font
Shifting signed 32-bit value by 31 bits is undefined, so changing significant bit to unsigned. The UBSAN warning calltrace like below:
UBSAN: shift-out-of-bounds in lib/fonts/fonts.c:139:20 left shift of 1 by 31 places cannot be represented in type 'int' <TASK> dump_stack_lvl+0x7d/0xa5 dump_stack+0x15/0x1b ubsan_epilogue+0xe/0x4e __ubsan_handle_shift_out_of_bounds+0x1e7/0x20c get_default_font+0x1c7/0x1f0 fbcon_startup+0x347/0x3a0 do_take_over_console+0xce/0x270 do_fbcon_takeover+0xa1/0x170 do_fb_registered+0x2a8/0x340 fbcon_fb_registered+0x47/0xe0 register_framebuffer+0x294/0x4a0 __drm_fb_helper_initial_config_and_unlock+0x43c/0x880 [drm_kms_helper] drm_fb_helper_initial_config+0x52/0x80 [drm_kms_helper] drm_fbdev_client_hotplug+0x156/0x1b0 [drm_kms_helper] drm_fbdev_generic_setup+0xfc/0x290 [drm_kms_helper] bochs_pci_probe+0x6ca/0x772 [bochs] local_pci_probe+0x4d/0xb0 pci_device_probe+0x119/0x320 really_probe+0x181/0x550 __driver_probe_device+0xc6/0x220 driver_probe_device+0x32/0x100 __driver_attach+0x195/0x200 bus_for_each_dev+0xbb/0x120 driver_attach+0x27/0x30 bus_add_driver+0x22e/0x2f0 driver_register+0xa9/0x190 __pci_register_driver+0x90/0xa0 bochs_pci_driver_init+0x52/0x1000 [bochs] do_one_initcall+0x76/0x430 do_init_module+0x61/0x28a load_module+0x1f82/0x2e50 __do_sys_finit_module+0xf8/0x190 __x64_sys_finit_module+0x23/0x30 do_syscall_64+0x58/0x80 entry_SYSCALL_64_after_hwframe+0x63/0xcd </TASK>
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade python-perf-debuginfoUpgrade kernel-debuginfo-common-x86_64Upgrade kernel-tools-debuginfoUpgrade kernel-headersUpgrade kernel-debuginfoUpgrade kernelUpgrade python-perfUpgrade kernel-livepatch-5.15.86-53.137Upgrade perf-debuginfoUpgrade perfUpgrade kernel-debuginfo-common-aarch64Upgrade bpftool-debuginfoUpgrade kernel-toolsUpgrade bpftoolUpgrade kernel-tools-develUpgrade kernel-livepatch-5.10.165-143.735Upgrade kernel-devel | May 20, 2026 | May 20, 2026 |
| Debian | — | Upgrade linux | Oct 9, 2025 | Oct 9, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade kernel-tools-libsUpgrade bpftoolUpgrade python3-perfUpgrade kernelUpgrade kernel-toolsUpgrade kernel-abi-stablelists | Feb 3, 2026 | Feb 2, 2026 |
| Redhat_linux | — | Upgrade kernelNo solution existsUpgrade kernel-rt | Nov 14, 2025 | Oct 7, 2025 |
| Ubuntu | — | Upgrade linux-gcp-fipsUpgrade linux-aws-5.15Upgrade linux-riscv-5.15Upgrade linux-oracleUpgrade linux-azureUpgrade linux-azure-5.15Upgrade linux-raspi-5.4Upgrade linux-bluefieldUpgrade linux-gkeUpgrade linux-oracle-5.4Upgrade linux-lowlatency-hwe-5.15Upgrade linux-gcpUpgrade linux-xilinx-zynqmpUpgrade linux-realtimeUpgrade linux-ibmUpgrade linux-gcp-5.15Upgrade linux-intel-iotg-5.15Upgrade linux-fipsUpgrade linux-intel-iot-realtimeUpgrade linux-intel-iotgUpgrade linux-kvmUpgrade linux-nvidiaUpgrade linux-hwe-5.4Upgrade linux-gkeopUpgrade linux-nvidia-tegra-5.15Upgrade linux-raspiUpgrade linux-gcp-5.4Upgrade linux-azure-fipsUpgrade linux-aws-fipsUpgrade linux-ibm-5.4Upgrade linux-lowlatencyUpgrade linux-hwe-5.15Upgrade linux-oracle-5.15Upgrade linux-iotUpgrade linux-awsUpgrade linux-azure-5.4Upgrade linuxUpgrade linux-aws-5.4 | Oct 10, 2025 | Oct 7, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Oct 15, 2025 | Oct 7, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub