CVE-2025-38612
Linux Kernel vulnerability analysis and mitigation

Overview

A memory leak vulnerability (CVE-2025-38612) was discovered in the Linux kernel's FBTFT framebuffer driver. The vulnerability was disclosed on August 19, 2025, affecting the staging FBTFT driver component. The issue occurs in the fbtft_framebuffer_alloc() function where memory allocated in fb_deferred_io_init() for info->pagerefs is not properly freed in error paths after successful fb_info structure allocation (NVD).

Technical details

The vulnerability stems from an incomplete cleanup in error handling paths within the FBTFT framebuffer driver. Specifically, when the fb_info structure is successfully allocated but subsequent operations fail, the memory allocated by fb_deferred_io_init() for the info->pagerefs structure remains unreleased. This oversight in the error path handling leads to memory leaks (NVD).

Impact

The vulnerability results in memory leaks in the Linux kernel's FBTFT framebuffer driver, which could lead to resource exhaustion over time. While the immediate impact may be minimal, sustained exploitation could potentially affect system stability and performance (NVD).

Mitigation and workarounds

The issue has been addressed by adding proper cleanup functions in the error path. The fix ensures that memory allocated for info->pagerefs is properly freed when errors occur during the framebuffer allocation process (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-68764N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-modules
NoYesJan 05, 2026
CVE-2025-68762N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug
NoYesJan 05, 2026
CVE-2025-68758N/AN/A
  • Linux KernelLinux Kernel
  • linux-riscv
NoYesJan 05, 2026
CVE-2025-68756N/AN/A
  • Linux KernelLinux Kernel
  • linux-fips
NoYesJan 05, 2026
CVE-2025-68753N/AN/A
  • Linux KernelLinux Kernel
  • python3-perf
NoYesJan 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management