In the Linux kernel, the following vulnerability has been resolved:
fbcon: fix integer overflow in fbcon_do_set_font
Fix integer overflow vulnerabilities in fbcon_do_set_font() where font size calculations could overflow when handling user-controlled font parameters.
The vulnerabilities occur when:
- CALC_FONTSZ(h, pitch, charcount) performs h * pith * charcount
- FONT_EXTRA_WORDS * sizeof(int) + size addition can also overflow
- This results in smaller allocations than expected, leading to buffer
Add explicit overflow checking using check_mul_overflow() and check_add_overflow() kernel helpers to safety validate all size calculations before allocation.