A memory-corruption vulnerability in the Linux kernel Framebuffer Console (fbcon), tracked as CVE-2023-38409, can allow a low-privileged local attacker to crash an affected system. Red Hat rates the flaw as moderate severity (CVSS 3.1: 5.5) and classifies it as CWE-129, improper validation of an array index; affected Red Hat Enterprise Linux 7 and 8 kernel and real-time kernel packages received security updates.
The defect affects kernels from version 5.19 and stems from set_con2fb_map() updating the con2fb_map framebuffer mapping only for the first virtual console it takes over. That behavior can leave framebuffer structures out of sync during mode deletion and trigger the memory-safety condition identified through KASAN. Linux fixed the issue in commit fffb0b52d5258554c645c966c6cbef7de50b851d; organizations should apply vendor kernel updates, or where patching is not immediately possible, prevent the fbcon module from loading by blacklisting it.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:1332 to fix CVE-2023-38409 in Red Hat Enterprise Linux 7 kernel-rt packages.
Red Hat issued RHSA-2024:1249 for RHEL 7 kernel packages and RHSA-2024:1268 for RHEL 8.2 kernel packages under multiple update services, fixing CVE-2023-38409.
Red Hat issued RHSA-2024:0562 for RHEL 8.4 Advanced Mission Critical Update Support kernel packages and RHSA-2024:0563 for RHEL 8.4 Telecommunications Update Service kernel-rt packages, addressing CVE-2023-38409.
Red Hat issued RHSA-2024:3138 for RHEL 8 kernel packages and RHSA-2024:2950 for RHEL 8 kernel-rt packages, addressing the fbcon memory-corruption vulnerability.
Linux committed fffb0b52d5258554c645c966c6cbef7de50b851d to correct set_con2fb_map() so it updates con2fb_map for every applicable virtual console, preventing framebuffer mapping arrays from falling out of sync. The patch, authored by Daniel Vetter, was marked for stable branches beginning with Linux v5.19.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.