Junglewise Threat Intelligence

CVE-2025-38702: Linux Kernel buffer overflow in fbdev do_register_framebuffer

CVE-2025-38702 · Severity: high · CVSS 7.8 · Published 2025-09-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's framebuffer device (fbdev) component could allow a local user to cause a system crash or potentially execute unauthorized code. The issue occurs when the system manages display buffers, where certain sequences of adding and removing displays can lead to memory corruption. This could impact the stability of the operating system or allow an attacker to gain higher privileges on the system.

Technical details

A buffer overflow exists in the 'do_register_framebuffer()' function within 'drivers/video/fbdev/core/fbmem.c'. The vulnerability is triggered when the 'registered_fb[]' array becomes fragmented due to the unregistration of framebuffers, creating NULL gaps. If the registration loop continues to search for an empty slot without a proper boundary check, it can exceed the 'FB_MAX' limit, leading to an out-of-bounds write. A local attacker with sufficient privileges to register framebuffers could exploit this to corrupt kernel memory, leading to a denial of service or local privilege escalation. Patches have been released across multiple stable kernel branches to add the necessary boundary checks.

Affected products

  • Linux Linux Kernel versions from 2.6.12.1 up to 6.1.149; 6.2 up to 6.6.103; 6.7 up to 6.12.43; 6.13 up to 6.15.11; 6.16 up to 6.16.2

Timeline

  • 2025-07-01: other: Vulnerability fixed in source code by author
  • 2025-09-04: disclosed: CVE published by kernel.org
  • 2025-09-04: patched: Patches available in various stable kernel releases

References

Related threats