In the Linux kernel, the following vulnerability has been resolved:
fbdev: fix potential buffer overflow in doregisterframebuffer()
The current implementation may lead to buffer overflow when: 1. Unregistration creates NULL gaps in registeredfb[] 2. All array slots become occupied despite numregisteredfb < FBMAX 3. The registration loop exceeds array bounds
Add boundary check to prevent registeredfb[FBMAX] access.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38702.json"
}[
{
"signature_version": "v1",
"digest": {
"length": 1547.0,
"function_hash": "87046133594454772441321762093923348966"
},
"deprecated": false,
"signature_type": "Function",
"id": "CVE-2025-38702-15798518",
"target": {
"function": "do_register_framebuffer",
"file": "drivers/video/fbdev/core/fbmem.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@806f85bdd3a60187c21437fc51baace11f659f35"
},
{
"signature_version": "v1",
"digest": {
"length": 1547.0,
"function_hash": "87046133594454772441321762093923348966"
},
"deprecated": false,
"signature_type": "Function",
"id": "CVE-2025-38702-1737c13e",
"target": {
"function": "do_register_framebuffer",
"file": "drivers/video/fbdev/core/fbmem.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2828a433c7d7a05b6f27c8148502095101dd0b09"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"155320975751818822069078599959896149151",
"268739677362432951790054750864187888978",
"6897441962384697582061541996028082531"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2025-38702-37f07745",
"target": {
"file": "drivers/video/fbdev/core/fbmem.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2828a433c7d7a05b6f27c8148502095101dd0b09"
},
{
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"155320975751818822069078599959896149151",
"268739677362432951790054750864187888978",
"6897441962384697582061541996028082531"
]
},
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2025-38702-910d72df",
"target": {
"file": "drivers/video/fbdev/core/fbmem.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@806f85bdd3a60187c21437fc51baace11f659f35"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-38702.json"