Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-99558.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-99558
Upstream
Published
2026-09-04T16:18:04Z
Modified
2026-09-05T14:17:04.559099916Z
Summary
CVE-2026-80786 affecting package kernel 6.6.150.1-1
Details

In the Linux kernel, the following vulnerability has been resolved:

fbdev: Wrap user-invoked calls to fbsetvar() in helper

Handle fbcon during display updates in fbsetvarfromuser(). Check with fbcon if the mode change is possible, update hardware state and finally update fbcon. Update all callers.

Only the FBIOPUT_VSCREENINFO ioctl currently does all steps. Other mode-changes callers in sysfs and driver code are missing fbcon-related steps.

With the new helper, ps3fb and shmobilelcdcfb no longer maintain fbcon state themselves.

References

Affected packages

Azure Linux:3 / kernel

Package

Name
kernel
Purl
pkg:rpm/azure-linux/kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
6.6.150.1-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-99558.json"