Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2025-38612— staging: fbtft: fix potential memory leak in fbtft_framebuffer_alloc()

AI Predicted 4.3 Difficulty: Moderate EPSS 0.02% · P7

Affected Version Matrix 20

VendorProductVersion RangeStatus
LinuxLinuxc296d5f9957c03994a699d6739c27d4581a9f6c7< 83ea0c7b8d12c67f6c4703d6c458627a7fc45fc0affected
c296d5f9957c03994a699d6739c27d4581a9f6c7< c3b1c45c48117ed4d8797ee89d1155f16b72d490affected
c296d5f9957c03994a699d6739c27d4581a9f6c7< 3290f62f23fae05f2ec34085eb86dfb3648ef91faffected
c296d5f9957c03994a699d6739c27d4581a9f6c7< 6f9e2cf9e9c1a891a683329af35bb33ed9d38b5faffected
c296d5f9957c03994a699d6739c27d4581a9f6c7< b31cf6f7716a5d3e4461763f32d812acdaec6e74affected
c296d5f9957c03994a699d6739c27d4581a9f6c7< a3177955f8da3c826a18b75e54881e2e9a9c96f1affected
c296d5f9957c03994a699d6739c27d4581a9f6c7< 6771f121ae87490ddc19eabb7450383af9e01b6daffected
c296d5f9957c03994a699d6739c27d4581a9f6c7< 47b3d6e8921bbb7b65c2dab8eaa8864901848c1caffected
… +12 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-38612

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
staging: fbtft: fix potential memory leak in fbtft_framebuffer_alloc()
Source: NVD (National Vulnerability Database)
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: staging: fbtft: fix potential memory leak in fbtft_framebuffer_alloc() In the error paths after fb_info structure is successfully allocated, the memory allocated in fb_deferred_io_init() for info->pagerefs is not freed. Fix that by adding the cleanup function on the error path.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于内存清理不当,可能导致内存泄漏。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux c296d5f9957c03994a699d6739c27d4581a9f6c7 ~ 83ea0c7b8d12c67f6c4703d6c458627a7fc45fc0 -
LinuxLinux 4.0 -

II. Public POCs for CVE-2025-38612

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-38612

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-08-19 · 60 CVEs total

CVE-2025-38593Bluetooth: hci_sync: fix double free in 'hci_discovery_filter_clear()'
CVE-2025-38614eventpoll: Fix semi-unbounded recursion
CVE-2025-38609PM / devfreq: Check governor before using governor->name
CVE-2025-38608bpf, ktls: Fix data corruption when using bpf_msg_pop_data() in ktls
CVE-2025-38607bpf: handle jset (if a & b ...) as a jump in CFG computation
CVE-2025-38610powercap: dtpm_cpu: Fix NULL pointer dereference in get_pd_power_uw()
CVE-2025-38597drm/rockchip: vop2: fail cleanly if missing a primary plane for a video-port
CVE-2025-38595xen: fix UAF in dmabuf_exp_from_pages()
CVE-2025-38596drm/panthor: Fix UAF in panthor_gem_create_with_handle() debugfs code
CVE-2025-38594iommu/vt-d: Fix UAF on sva unbind with pending IOPFs
CVE-2025-38598drm/amdgpu: fix use-after-free in amdgpu_userq_suspend+0x51a/0x5a0
CVE-2025-38592Bluetooth: hci_devcd_dump: fix out-of-bounds via dev_coredumpv
CVE-2025-38591bpf: Reject narrower access to pointer ctx fields
CVE-2025-38590net/mlx5e: Remove skb secpath if xfrm state is not found
CVE-2025-38589neighbour: Fix null-ptr-deref in neigh_flush_dev().
CVE-2025-38588ipv6: prevent infinite loop in rt6_nlmsg_size()
CVE-2025-38587ipv6: fix possible infinite loop in fib6_info_uses_dev()
CVE-2025-38586bpf, arm64: Fix fp initialization for exception boundary
CVE-2025-38585staging: media: atomisp: Fix stack buffer overflow in gmin_get_var_int()
CVE-2025-38584padata: Fix pd UAF once and for all

Showing top 20 of 60 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-38612

No comments yet


Leave a comment