CVE-2026-23236 (GCVE-0-2026-23236)
Vulnerability from cvelistv5
Published
2026-03-04 14:36
Modified
2026-08-05 12:20
Summary
In the Linux kernel, the following vulnerability has been resolved: fbdev: smscufx: properly copy ioctl memory to kernelspace The UFX_IOCTL_REPORT_DAMAGE ioctl does not properly copy data from userspace to kernelspace, and instead directly references the memory, which can cause problems if invalid data is passed from userspace. Fix this all up by correctly copying the memory before accessing it within the kernel.
Impacted products
Vendor Product Version
Linux Linux Version: 3c8a63e22a0802fd56380f6ab305b419f18eb6f5
Version: 3c8a63e22a0802fd56380f6ab305b419f18eb6f5
Version: 3c8a63e22a0802fd56380f6ab305b419f18eb6f5
Version: 3c8a63e22a0802fd56380f6ab305b419f18eb6f5
Version: 3c8a63e22a0802fd56380f6ab305b419f18eb6f5
Version: 3c8a63e22a0802fd56380f6ab305b419f18eb6f5
Version: 3c8a63e22a0802fd56380f6ab305b419f18eb6f5
Version: 3c8a63e22a0802fd56380f6ab305b419f18eb6f5
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "affected": [
          {
            "defaultStatus": "unknown",
            "product": "RUGGEDCOM RST2428P",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "V4.0",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-06-02T13:01:07.977Z",
          "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
          "shortName": "siemens-SADP"
        },
        "references": [
          {
            "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
          }
        ],
        "x_adpType": "supplier"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/video/fbdev/smscufx.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "061cfeb560aa3ddc174153dbe5be9d0b55eb7248",
              "status": "affected",
              "version": "3c8a63e22a0802fd56380f6ab305b419f18eb6f5",
              "versionType": "git"
            },
            {
              "lessThan": "6167af934f956d3ae1e06d61f45cd0d1004bbe1a",
              "status": "affected",
              "version": "3c8a63e22a0802fd56380f6ab305b419f18eb6f5",
              "versionType": "git"
            },
            {
              "lessThan": "a0321e6e58facb39fe191caa0e52ed9aab6a48fe",
              "status": "affected",
              "version": "3c8a63e22a0802fd56380f6ab305b419f18eb6f5",
              "versionType": "git"
            },
            {
              "lessThan": "0634e8d650993602fc5b389ff7ac525f6542e141",
              "status": "affected",
              "version": "3c8a63e22a0802fd56380f6ab305b419f18eb6f5",
              "versionType": "git"
            },
            {
              "lessThan": "52917e265aa5f848212f60fc50fc504d8ef12866",
              "status": "affected",
              "version": "3c8a63e22a0802fd56380f6ab305b419f18eb6f5",
              "versionType": "git"
            },
            {
              "lessThan": "1c008ad0f0d1c1523902b9cdb08e404129677bfc",
              "status": "affected",
              "version": "3c8a63e22a0802fd56380f6ab305b419f18eb6f5",
              "versionType": "git"
            },
            {
              "lessThan": "f1e91bd4efeae48b0f42caed7e8ce2e3a0d05b02",
              "status": "affected",
              "version": "3c8a63e22a0802fd56380f6ab305b419f18eb6f5",
              "versionType": "git"
            },
            {
              "lessThan": "120adae7b42faa641179270c067864544a50ab69",
              "status": "affected",
              "version": "3c8a63e22a0802fd56380f6ab305b419f18eb6f5",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/video/fbdev/smscufx.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.2"
            },
            {
              "lessThan": "3.2",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.251",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.201",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.164",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.127",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.74",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.13",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.19.*",
              "status": "unaffected",
              "version": "6.19.3",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.0",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.251",
                  "versionStartIncluding": "3.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.201",
                  "versionStartIncluding": "3.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.164",
                  "versionStartIncluding": "3.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.127",
                  "versionStartIncluding": "3.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.74",
                  "versionStartIncluding": "3.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.13",
                  "versionStartIncluding": "3.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.19.3",
                  "versionStartIncluding": "3.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.0",
                  "versionStartIncluding": "3.2",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: smscufx: properly copy ioctl memory to kernelspace\n\nThe UFX_IOCTL_REPORT_DAMAGE ioctl does not properly copy data from\nuserspace to kernelspace, and instead directly references the memory,\nwhich can cause problems if invalid data is passed from userspace.  Fix\nthis all up by correctly copying the memory before accessing it within\nthe kernel."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerability is triggered via a local ioctl syscall (UFX_IOCTL_REPORT_DAMAGE) on the /dev/fb* framebuffer device file. The USB device must be physically present but the attack itself is a local system call.\nAC:L - The attacker can reliably trigger the vulnerability with a single ioctl call. No race condition, special timing, or non-default configuration is required.\nPR:L - Opening /dev/fb* typically requires membership in the video group, which is a low-privilege requirement on desktop/workstation systems. No capabilities or root privileges are needed beyond device file access.\nUI:N - No user interaction is required. The attacker independently issues the ioctl to trigger the vulnerability.\nS:U - The vulnerability stays within the kernel\u0027s security scope \u2014 there is no escape from a VM, container, or other security boundary.\nC:L - On non-SMAP systems, the kernel reads 16 bytes (struct dloarea: x, y, w, h) from an attacker-controlled kernel address, providing a limited information disclosure primitive through side-channel observation of the subsequent conditional writes and USB transfer behavior.\nI:H - On non-SMAP systems, the kernel conditionally writes constrained values (0 or display resolution integers) to attacker-controlled kernel addresses, providing a write-what-where primitive. Writing 0 to arbitrary kernel addresses is a known exploitation technique for privilege escalation.\nA:H - On SMAP-enabled systems (most modern x86), the direct userspace pointer dereference causes a kernel oops or panic, reliably crashing the system. Even on non-SMAP systems, passing invalid addresses triggers a kernel fault."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:20:48.788Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/061cfeb560aa3ddc174153dbe5be9d0b55eb7248"
        },
        {
          "url": "https://git.kernel.org/stable/c/6167af934f956d3ae1e06d61f45cd0d1004bbe1a"
        },
        {
          "url": "https://git.kernel.org/stable/c/a0321e6e58facb39fe191caa0e52ed9aab6a48fe"
        },
        {
          "url": "https://git.kernel.org/stable/c/0634e8d650993602fc5b389ff7ac525f6542e141"
        },
        {
          "url": "https://git.kernel.org/stable/c/52917e265aa5f848212f60fc50fc504d8ef12866"
        },
        {
          "url": "https://git.kernel.org/stable/c/1c008ad0f0d1c1523902b9cdb08e404129677bfc"
        },
        {
          "url": "https://git.kernel.org/stable/c/f1e91bd4efeae48b0f42caed7e8ce2e3a0d05b02"
        },
        {
          "url": "https://git.kernel.org/stable/c/120adae7b42faa641179270c067864544a50ab69"
        }
      ],
      "title": "fbdev: smscufx: properly copy ioctl memory to kernelspace",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-23236",
    "datePublished": "2026-03-04T14:36:40.162Z",
    "dateReserved": "2026-01-13T15:37:45.988Z",
    "dateUpdated": "2026-08-05T12:20:48.788Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…