A flaw was found in the Framebuffer Console (fbcon) in the Linux Kernel. When providing font->width and font->height greater than 32 to fbcon_set_font, since there are no checks in place, a shift-out-of-bounds occurs leading to undefined behavior and possible denial of service. Upstream fix: https://github.com/torvalds/linux/commit/2b09d5d364986f724f17001ccfe4126b9b43a0be
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 2213490]
This was fixed for Fedora with the 6.1.11 stable kernel updates.