In the Linux kernel, the following vulnerability has been resolved:
fbdev: fix potential buffer overflow in doregisterframebuffer()
The current implementation may lead to buffer overflow when: 1. Unregistration creates NULL gaps in registeredfb[] 2. All array slots become occupied despite numregisteredfb < FBMAX 3. The registration loop exceeds array bounds
Add boundary check to prevent registeredfb[FBMAX] access.
[
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 1619.0,
"function_hash": "165960799319566798143118780705865958974"
},
"target": {
"file": "drivers/video/fbdev/core/fbmem.c",
"function": "do_register_framebuffer"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@523b84dc7ccea9c4d79126d6ed1cf9033cf83b05",
"signature_version": "v1",
"id": "CVE-2025-38702-07ade32a"
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"155320975751818822069078599959896149151",
"268739677362432951790054750864187888978",
"6897441962384697582061541996028082531"
],
"threshold": 0.9
},
"target": {
"file": "drivers/video/fbdev/core/fbmem.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@523b84dc7ccea9c4d79126d6ed1cf9033cf83b05",
"signature_version": "v1",
"id": "CVE-2025-38702-117ec1c3"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 1547.0,
"function_hash": "87046133594454772441321762093923348966"
},
"target": {
"file": "drivers/video/fbdev/core/fbmem.c",
"function": "do_register_framebuffer"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@806f85bdd3a60187c21437fc51baace11f659f35",
"signature_version": "v1",
"id": "CVE-2025-38702-15798518"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 1547.0,
"function_hash": "87046133594454772441321762093923348966"
},
"target": {
"file": "drivers/video/fbdev/core/fbmem.c",
"function": "do_register_framebuffer"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2828a433c7d7a05b6f27c8148502095101dd0b09",
"signature_version": "v1",
"id": "CVE-2025-38702-1737c13e"
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"155320975751818822069078599959896149151",
"268739677362432951790054750864187888978",
"6897441962384697582061541996028082531"
],
"threshold": 0.9
},
"target": {
"file": "drivers/video/fbdev/core/fbmem.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2828a433c7d7a05b6f27c8148502095101dd0b09",
"signature_version": "v1",
"id": "CVE-2025-38702-37f07745"
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"155320975751818822069078599959896149151",
"268739677362432951790054750864187888978",
"6897441962384697582061541996028082531"
],
"threshold": 0.9
},
"target": {
"file": "drivers/video/fbdev/core/fbmem.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@248b2aab9b2af5ecf89d9d7955a2ff20c4b4a399",
"signature_version": "v1",
"id": "CVE-2025-38702-5ae2b900"
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"155320975751818822069078599959896149151",
"268739677362432951790054750864187888978",
"6897441962384697582061541996028082531"
],
"threshold": 0.9
},
"target": {
"file": "drivers/video/fbdev/core/fbmem.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@cbe740de32bb0fb7a5213731ff5f26ea6718fca3",
"signature_version": "v1",
"id": "CVE-2025-38702-79ed709f"
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"155320975751818822069078599959896149151",
"268739677362432951790054750864187888978",
"6897441962384697582061541996028082531"
],
"threshold": 0.9
},
"target": {
"file": "drivers/video/fbdev/core/fbmem.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@806f85bdd3a60187c21437fc51baace11f659f35",
"signature_version": "v1",
"id": "CVE-2025-38702-910d72df"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 1619.0,
"function_hash": "165960799319566798143118780705865958974"
},
"target": {
"file": "drivers/video/fbdev/core/fbmem.c",
"function": "do_register_framebuffer"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@248b2aab9b2af5ecf89d9d7955a2ff20c4b4a399",
"signature_version": "v1",
"id": "CVE-2025-38702-aaad959c"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 1449.0,
"function_hash": "164747607683516488663563635974758388589"
},
"target": {
"file": "drivers/video/fbdev/core/fbmem.c",
"function": "do_register_framebuffer"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@cbe740de32bb0fb7a5213731ff5f26ea6718fca3",
"signature_version": "v1",
"id": "CVE-2025-38702-d644da0d"
}
]