SB2025071165 - Input validation error in Linux kernel fbdev core driver
Published: July 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2025-38312)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the fb_find_mode_cvt() function in drivers/video/fbdev/core/fbcvt.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2d63433e8eaa3c91b2948190e395bc67009db0d9
- https://git.kernel.org/stable/c/3f6dae09fc8c306eb70fdfef70726e1f154e173a
- https://git.kernel.org/stable/c/53784073cbad18f75583fd3da9ffdfc4d1f05405
- https://git.kernel.org/stable/c/54947530663edcbaaee1314c01fdd8c72861b124
- https://git.kernel.org/stable/c/610f247f2772e4f92b63442125a1b7ade79898d8
- https://git.kernel.org/stable/c/9027ce4c037b566b658b8939a76326b7125e3627
- https://git.kernel.org/stable/c/ab91647acdf43b984824776559a452212eaeb21a
- https://git.kernel.org/stable/c/b235393b9f43ff86a38ca2bde6372312ea215dc5