Vulnerability in fbdev exploited by attaching a malicious output device

In the fbdev (Framebuffer) subsystem, vulnerability, which can lead to a 64-byte kernel stack overflow when handling malformed EDID parameters. Exploitation can be carried out by connecting a malicious monitor, projector or other output device (for example, a specially prepared device simulating a monitor) to the computer. Interestingly, the first to be notified of a vulnerability responded Linus Torvalds, who proposed personally written patch with correction.

Source: opennet.ru

Add a comment