{"id":"DEBIAN-CVE-2025-38214","details":"In the Linux kernel, the following vulnerability has been resolved:  fbdev: Fix fb_set_var to prevent null-ptr-deref in fb_videomode_to_var  If fb_add_videomode() in fb_set_var() fails to allocate memory for fb_videomode, later it may lead to a null-ptr dereference in fb_videomode_to_var(), as the fb_info is registered while not having the mode in modelist that is expected to be there, i.e. the one that is described in fb_info-\u003evar.  ================================================================ general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] PREEMPT SMP KASAN NOPTI KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f] CPU: 1 PID: 30371 Comm: syz-executor.1 Not tainted 5.10.226-syzkaller #0 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014 RIP: 0010:fb_videomode_to_var+0x24/0x610 drivers/video/fbdev/core/modedb.c:901 Call Trace:  display_to_var+0x3a/0x7c0 drivers/video/fbdev/core/fbcon.c:929  fbcon_resize+0x3e2/0x8f0 drivers/video/fbdev/core/fbcon.c:2071  resize_screen drivers/tty/vt/vt.c:1176 [inline]  vc_do_resize+0x53a/0x1170 drivers/tty/vt/vt.c:1263  fbcon_modechanged+0x3ac/0x6e0 drivers/video/fbdev/core/fbcon.c:2720  fbcon_update_vcs+0x43/0x60 drivers/video/fbdev/core/fbcon.c:2776  do_fb_ioctl+0x6d2/0x740 drivers/video/fbdev/core/fbmem.c:1128  fb_ioctl+0xe7/0x150 drivers/video/fbdev/core/fbmem.c:1203  vfs_ioctl fs/ioctl.c:48 [inline]  __do_sys_ioctl fs/ioctl.c:753 [inline]  __se_sys_ioctl fs/ioctl.c:739 [inline]  __x64_sys_ioctl+0x19a/0x210 fs/ioctl.c:739  do_syscall_64+0x33/0x40 arch/x86/entry/common.c:46  entry_SYSCALL_64_after_hwframe+0x67/0xd1 ================================================================  The reason is that fb_info-\u003evar is being modified in fb_set_var(), and then fb_videomode_to_var() is called. If it fails to add the mode to fb_info-\u003emodelist, fb_set_var() returns error, but does not restore the old value of fb_info-\u003evar. Restore fb_info-\u003evar on failure the same way it is done earlier in the function.  Found by Linux Verification Center (linuxtesting.org) with Syzkaller.","modified":"2026-09-01T20:05:48.111538600Z","published":"2025-07-04T14:15:29.843Z","upstream":["CVE-2025-38214"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-38214"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.147-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.112-1","6.1.115-1","6.1.119-1","6.1.123-1","6.1.124-1","6.1.128-1","6.1.129-1","6.1.133-1","6.1.135-1","6.1.137-1","6.1.139-1","6.1.140-1","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38214.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.35-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38214.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.35-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38214.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}