CVE-2026-63949

Source
https://cve.org/CVERecord?id=CVE-2026-63949
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63949.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63949
Downstream
Published
2026-07-19T14:55:42.679Z
Modified
2026-07-21T03:47:25.309981216Z
Summary
auxdisplay: line-display: fix OOB read on zero-length message_store()
Details

In the Linux kernel, the following vulnerability has been resolved:

auxdisplay: line-display: fix OOB read on zero-length message_store()

linedisp_display() unconditionally reads msg[count - 1] before checking whether count is zero, so a write of zero bytes to the message sysfs attribute hits msg[-1]:

write(fd, "", 0);

-> message_store(..., buf, count=0)
   -> linedisp_display(linedisp, buf, count=0)
      -> msg[count - 1] == '\n'  ; OOB read

The kernfs write buffer for that store is a 1-byte allocation (kernfsfopwriteiter() does kmalloc(len + 1) with len == 0), so msg[-1] is a 1-byte read before the slab object. On a KASAN-enabled kernel this trips an out-of-bounds report and panics; on stock kernels it silently reads adjacent slab data and, if that byte happens to be '\n', the following count-- wraps ssizet 0 to -1 and is then passed to kmemdup_nul().

linedispdisplay() is reached from the messagestore() sysfs callback (drivers/auxdisplay/line-display.c message attribute, mode 0644) and from the in-tree initial-message setup with count == -1, so the OOB path is only userspace-triggerable via zero-byte writes; vfswrite() does not short-circuit on count == 0 and kernfsfopwriteiter() dispatches the store callback regardless.

Guard the trailing-newline trim with a count check. The existing if (!count) block then takes the clear-display path unchanged.

Affects every auxdisplay driver that registers via linedispregister() / linedispattach(): ht16k33, max6959, img-ascii-lcd, seg-led-gpio.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63949.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
7e76aece6f036cb7ada4858d6aa73825bfe22983
Fixed
ca5b0781946d5083ceafa752141f47f085853620
Fixed
8776032fe989a9b5fc77f2de5e03e4adb44c630e
Fixed
3859960daeb9b7b39b9847b5b0113bc6081eb735
Fixed
197476b126010bac1b3199833c6966cd6f54c2a9
Fixed
6ad4f75ef9f3372fce8cad494e789ac6a5507bef
Fixed
a7511dcd9dd4bc55d123f9b800c8a4ed2662e5c6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63949.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.176
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.143
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.93
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.35
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.12

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63949.json"