CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's framebuffer device (fbdev), where the `mode_string()` function can write beyond the allocated buffer size due to improper handling of return values from `snprintf()`. This flaw can lead to a buffer overflow, potentially allowing an attacker to manipulate kernel memory, resulting in system instability or privilege escalation. Organizations using affected versions of the Linux kernel should prioritize patching this vulnerability to safeguard against potential exploitation.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: fbdev: bound mode sysfs output to the sysfs buffer mode_string() uses snprintf() which can return a value larger than the remaining buffer space. show_modes() accumulates the return value into i without checking whether i has reached PAGE_SIZE, causing the offset to advance past the sysfs buffer if the modelist is long enough. Add a size parameter to mode_string() and use scnprintf() to return only the bytes actually written. Add an early return when offset already exceeds the buffer. In show_modes(), stop accumulating once the buffer is full.