CVE-2022-49948 (GCVE-0-2022-49948)

Vulnerability from cvelistv5 – Published: 2025-06-18 11:00 – Updated: 2025-12-23 13:26
VLAI?
Title
vt: Clear selection before changing the font
Summary
In the Linux kernel, the following vulnerability has been resolved: vt: Clear selection before changing the font When changing the console font with ioctl(KDFONTOP) the new font size can be bigger than the previous font. A previous selection may thus now be outside of the new screen size and thus trigger out-of-bounds accesses to graphics memory if the selection is removed in vc_do_resize(). Prevent such out-of-memory accesses by dropping the selection before the various con_font_set() console handlers are called.
Severity ?
No CVSS data available.
Assigner
Impacted products
Vendor Product Version
Linux Linux Affected: 009e39ae44f4191188aeb6dfbf661b771dbbe515 , < c555cf04684fde39b5b0dd9fd80730030ee10c4a (git)
Affected: 009e39ae44f4191188aeb6dfbf661b771dbbe515 , < e9ba4611ddf676194385506222cce7b0844e708e (git)
Affected: 009e39ae44f4191188aeb6dfbf661b771dbbe515 , < f74b4a41c5d7c9522469917e3072e55d435efd9e (git)
Affected: 009e39ae44f4191188aeb6dfbf661b771dbbe515 , < 1cf1930369c9dc428d827b60260c53271bff3285 (git)
Affected: 009e39ae44f4191188aeb6dfbf661b771dbbe515 , < 989201bb8c00b222235aff04e6200230d29dc7bb (git)
Affected: 009e39ae44f4191188aeb6dfbf661b771dbbe515 , < 2535431ae967ad17585513649625fea7db28d4db (git)
Affected: 009e39ae44f4191188aeb6dfbf661b771dbbe515 , < c904fe03c4bd1f356a58797d39e2a5d0ca15cefc (git)
Affected: 009e39ae44f4191188aeb6dfbf661b771dbbe515 , < 566f9c9f89337792070b5a6062dff448b3e7977f (git)
Affected: e60f8fcce05042e8f8cea25ee81fecc1222114cf (git)
Affected: 5812a9bc9d68a82c2cc839f88e6f7a05093ab39d (git)
Affected: 863ad19fd654c485e3beec3575c4d74a1e74369e (git)
Affected: dbc3fd44f957a39407e889287bf61fa0ef3ecc14 (git)
Affected: 0b2a0a58ad22f9d6dfc641bc5ec46057493f22a5 (git)
Affected: 9f2d48f0745f921040df91bfe8fa7f0339cd7497 (git)
Affected: 3425e397fb23cc2e8e6fb8f5b8226dcb447e84dd (git)
Affected: eeae0a12a16650ff494d5faefa371cd9e7079575 (git)
Create a notification for this product.
    Linux Linux Affected: 4.9
Unaffected: 0 , < 4.9 (semver)
Unaffected: 4.9.328 , ≤ 4.9.* (semver)
Unaffected: 4.14.293 , ≤ 4.14.* (semver)
Unaffected: 4.19.258 , ≤ 4.19.* (semver)
Unaffected: 5.4.213 , ≤ 5.4.* (semver)
Unaffected: 5.10.142 , ≤ 5.10.* (semver)
Unaffected: 5.15.66 , ≤ 5.15.* (semver)
Unaffected: 5.19.8 , ≤ 5.19.* (semver)
Unaffected: 6.0 , ≤ * (original_commit_for_fix)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/tty/vt/vt.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "c555cf04684fde39b5b0dd9fd80730030ee10c4a",
              "status": "affected",
              "version": "009e39ae44f4191188aeb6dfbf661b771dbbe515",
              "versionType": "git"
            },
            {
              "lessThan": "e9ba4611ddf676194385506222cce7b0844e708e",
              "status": "affected",
              "version": "009e39ae44f4191188aeb6dfbf661b771dbbe515",
              "versionType": "git"
            },
            {
              "lessThan": "f74b4a41c5d7c9522469917e3072e55d435efd9e",
              "status": "affected",
              "version": "009e39ae44f4191188aeb6dfbf661b771dbbe515",
              "versionType": "git"
            },
            {
              "lessThan": "1cf1930369c9dc428d827b60260c53271bff3285",
              "status": "affected",
              "version": "009e39ae44f4191188aeb6dfbf661b771dbbe515",
              "versionType": "git"
            },
            {
              "lessThan": "989201bb8c00b222235aff04e6200230d29dc7bb",
              "status": "affected",
              "version": "009e39ae44f4191188aeb6dfbf661b771dbbe515",
              "versionType": "git"
            },
            {
              "lessThan": "2535431ae967ad17585513649625fea7db28d4db",
              "status": "affected",
              "version": "009e39ae44f4191188aeb6dfbf661b771dbbe515",
              "versionType": "git"
            },
            {
              "lessThan": "c904fe03c4bd1f356a58797d39e2a5d0ca15cefc",
              "status": "affected",
              "version": "009e39ae44f4191188aeb6dfbf661b771dbbe515",
              "versionType": "git"
            },
            {
              "lessThan": "566f9c9f89337792070b5a6062dff448b3e7977f",
              "status": "affected",
              "version": "009e39ae44f4191188aeb6dfbf661b771dbbe515",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e60f8fcce05042e8f8cea25ee81fecc1222114cf",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5812a9bc9d68a82c2cc839f88e6f7a05093ab39d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "863ad19fd654c485e3beec3575c4d74a1e74369e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "dbc3fd44f957a39407e889287bf61fa0ef3ecc14",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0b2a0a58ad22f9d6dfc641bc5ec46057493f22a5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9f2d48f0745f921040df91bfe8fa7f0339cd7497",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3425e397fb23cc2e8e6fb8f5b8226dcb447e84dd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "eeae0a12a16650ff494d5faefa371cd9e7079575",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/tty/vt/vt.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.9"
            },
            {
              "lessThan": "4.9",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "4.9.*",
              "status": "unaffected",
              "version": "4.9.328",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "4.14.*",
              "status": "unaffected",
              "version": "4.14.293",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "4.19.*",
              "status": "unaffected",
              "version": "4.19.258",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.4.*",
              "status": "unaffected",
              "version": "5.4.213",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.142",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.66",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.19.*",
              "status": "unaffected",
              "version": "5.19.8",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.0",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "4.9.328",
                  "versionStartIncluding": "4.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "4.14.293",
                  "versionStartIncluding": "4.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "4.19.258",
                  "versionStartIncluding": "4.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.4.213",
                  "versionStartIncluding": "4.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.142",
                  "versionStartIncluding": "4.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.66",
                  "versionStartIncluding": "4.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.19.8",
                  "versionStartIncluding": "4.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.0",
                  "versionStartIncluding": "4.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "3.2.85",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "3.10.105",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "3.12.68",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "3.16.40",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "3.18.45",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "4.1.36",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "4.4.31",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "4.8.7",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvt: Clear selection before changing the font\n\nWhen changing the console font with ioctl(KDFONTOP) the new font size\ncan be bigger than the previous font. A previous selection may thus now\nbe outside of the new screen size and thus trigger out-of-bounds\naccesses to graphics memory if the selection is removed in\nvc_do_resize().\n\nPrevent such out-of-memory accesses by dropping the selection before the\nvarious con_font_set() console handlers are called."
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2025-12-23T13:26:12.987Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c555cf04684fde39b5b0dd9fd80730030ee10c4a"
        },
        {
          "url": "https://git.kernel.org/stable/c/e9ba4611ddf676194385506222cce7b0844e708e"
        },
        {
          "url": "https://git.kernel.org/stable/c/f74b4a41c5d7c9522469917e3072e55d435efd9e"
        },
        {
          "url": "https://git.kernel.org/stable/c/1cf1930369c9dc428d827b60260c53271bff3285"
        },
        {
          "url": "https://git.kernel.org/stable/c/989201bb8c00b222235aff04e6200230d29dc7bb"
        },
        {
          "url": "https://git.kernel.org/stable/c/2535431ae967ad17585513649625fea7db28d4db"
        },
        {
          "url": "https://git.kernel.org/stable/c/c904fe03c4bd1f356a58797d39e2a5d0ca15cefc"
        },
        {
          "url": "https://git.kernel.org/stable/c/566f9c9f89337792070b5a6062dff448b3e7977f"
        }
      ],
      "title": "vt: Clear selection before changing the font",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2022-49948",
    "datePublished": "2025-06-18T11:00:12.364Z",
    "dateReserved": "2025-06-18T10:57:27.382Z",
    "dateUpdated": "2025-12-23T13:26:12.987Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.


Loading…

Detection rules are retrieved from Rulezet.

Loading…

Loading…