CVE-2025-38630

In the Linux kernel, the following vulnerability has been resolved: fbdev: imxfb: Check fb_add_videomode to prevent null-ptr-deref fb_add_videomode() can fail with -ENOMEM when its internal kmalloc() cannot allocate a struct fb_modelist. If that happens, the modelist stays empty but the driver continues to register. Add a check for its return value to prevent poteintial null-ptr-deref, which is similar to the commit 17186f1f90d3 ("fbdev: Fix do_register_framebuffer to prevent null-ptr-deref in fb_videomode_to_var").
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

History

07 Jan 2026, 16:34

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE CWE-476
CPE cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
First Time Linux
Debian
Debian debian Linux
Linux linux Kernel
References () https://git.kernel.org/stable/c/40f0a51f6c54d46a94b9f1180339ede7ca7ee190 - () https://git.kernel.org/stable/c/40f0a51f6c54d46a94b9f1180339ede7ca7ee190 - Patch
References () https://git.kernel.org/stable/c/49377bac9e3bec1635065a033c9679214fe7593e - () https://git.kernel.org/stable/c/49377bac9e3bec1635065a033c9679214fe7593e - Patch
References () https://git.kernel.org/stable/c/4b5d36cc3014986e6fac12eaa8433fe56801d4ce - () https://git.kernel.org/stable/c/4b5d36cc3014986e6fac12eaa8433fe56801d4ce - Patch
References () https://git.kernel.org/stable/c/69373502c2b5d364842c702c941d1171e4f35a7c - () https://git.kernel.org/stable/c/69373502c2b5d364842c702c941d1171e4f35a7c - Patch
References () https://git.kernel.org/stable/c/ac16154cccda8be10ee3ae188f10a06f3890bc5d - () https://git.kernel.org/stable/c/ac16154cccda8be10ee3ae188f10a06f3890bc5d - Patch
References () https://git.kernel.org/stable/c/cca8f5a3991916729b39d797d01499c335137319 - () https://git.kernel.org/stable/c/cca8f5a3991916729b39d797d01499c335137319 - Patch
References () https://git.kernel.org/stable/c/da11e6a30e0bb8e911288bdc443b3dc8f6a7cac7 - () https://git.kernel.org/stable/c/da11e6a30e0bb8e911288bdc443b3dc8f6a7cac7 - Patch
References () https://git.kernel.org/stable/c/f00c29e6755ead56baf2a9c1d3c4c0bb40af3612 - () https://git.kernel.org/stable/c/f00c29e6755ead56baf2a9c1d3c4c0bb40af3612 - Patch
References () https://git.kernel.org/stable/c/f060441c153495750804133555cf0a211a856892 - () https://git.kernel.org/stable/c/f060441c153495750804133555cf0a211a856892 - Patch
References () https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html - () https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html - Third Party Advisory

03 Nov 2025, 18:16

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html -

28 Aug 2025, 15:15

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/69373502c2b5d364842c702c941d1171e4f35a7c -
  • () https://git.kernel.org/stable/c/cca8f5a3991916729b39d797d01499c335137319 -
  • () https://git.kernel.org/stable/c/f00c29e6755ead56baf2a9c1d3c4c0bb40af3612 -
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: fbdev: imxfb: Comprobar fb_add_videomode para evitar la desreferencia de PTR nula. fb_add_videomode() puede fallar con -ENOMEM cuando su función interna kmalloc() no puede asignar una estructura fb_modelist. En tal caso, la estructura de modelist permanece vacía, pero el controlador continúa registrándose. Se ha añadido una comprobación de su valor de retorno para evitar una posible desreferencia de PTR nula, similar al commit 17186f1f90d3 ("fbdev: Corregir do_register_framebuffer para evitar la desreferencia de PTR nula en fb_videomode_to_var").

22 Aug 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-22 16:15

Updated : 2026-01-07 16:34


NVD link : CVE-2025-38630

Mitre link : CVE-2025-38630

CVE.ORG link : CVE-2025-38630


JSON object : View

Products Affected

debian

  • debian_linux

linux

  • linux_kernel
CWE
CWE-476

NULL Pointer Dereference