CVE-2025-68296 addresses a race condition in the Linux kernel's drm, fbcon, and vga_switcheroo components, specifically affecting the fbcon setup during VGA switching. This vulnerability could lead to out-of-bounds (OOB) access in fbcon_remap_all() due to a lack of proper console lock protection. While a CVSS score is not available, the FAUCET Risk Score of 7/100 suggests a low to moderate severity, with the potential impact being system instability or crashes. There is no known active exploitation, public exploit code, or Metasploit/Nuclei modules, though it has garnered some community discussion and media coverage, including a security update from openSUSE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 2.6.34CNA affecteddefault affected | |
| Linux | Linux | >= 6a9ee8af344e3bd7dbd61e67037096cdf7f83289, < 05814c389b53d2f3a0b9eeb90ba7a05ba77c4c2a, >= 6a9ee8af344e3bd7dbd61e67037096cdf7f83289, < 482330f8261b4bea8146d9bd69c1199e5dfcbb5c, >= 6a9ee8af344e3bd7dbd61e67037096cdf7f83289, < 711ebd961190def4c69ea24b2f0be75e995af24a, >= 6a9ee8af344e3bd7dbd61e67037096cdf7f83289, < eb76d0f5553575599561010f24c277cc5b31d003CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
Linux kernel (OEM) vulnerabilities
Apr 6, 2026Linux kernel (Raspberry Pi) vulnerabilities
Apr 1, 2026Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Real-time) vulnerabilities
Mar 23, 2026Linux kernel vulnerabilities
Mar 17, 2026Linux kernel vulnerabilities
Mar 16, 2026kernel: Linux kernel: Denial of Service due to race condition in fbcon setup
Dec 16, 2025drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup
Dec 9, 2025