CVE-2025-38702: Debian Linux

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: fbdev: fix potential buffer overflow in do_register_framebuffer() The current implementation may lead to buffer overflow when: 1. Unregistration creates NULL gaps in registered_fb[] 2. All array slots become occupied despite num_registered_fb < FB_MAX 3. The registration loop exceeds array bounds Add boundary check to prevent registered_fb[FB_MAX] access.

Affected products

  • Debian Debian Linux: version 11.0 only
  • Linux Linux Kernel: from 2.6.12.1, before 6.1.149 (fixed in 6.1.149); from 6.2, before 6.6.103 (fixed in 6.6.103); from 6.7, before 6.12.43 (fixed in 6.12.43); from 6.13, before 6.15.11 (fixed in 6.15.11); from 6.16, before 6.16.2 (fixed in 6.16.2); version 2.6.12 only

Published 2025-09-04. Last modified 2026-06-17.