CVE-2025-37851

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/05/2025
Last modified:
17/11/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> fbdev: omapfb: Add &amp;#39;plane&amp;#39; value check<br /> <br /> Function dispc_ovl_setup is not intended to work with the value OMAP_DSS_WB<br /> of the enum parameter plane.<br /> <br /> The value of this parameter is initialized in dss_init_overlays and in the<br /> current state of the code it cannot take this value so it&amp;#39;s not a real<br /> problem.<br /> <br /> For the purposes of defensive coding it wouldn&amp;#39;t be superfluous to check<br /> the parameter value, because some functions down the call stack process<br /> this value correctly and some not.<br /> <br /> For example, in dispc_ovl_setup_global_alpha it may lead to buffer<br /> overflow.<br /> <br /> Add check for this value.<br /> <br /> Found by Linux Verification Center (linuxtesting.org) with SVACE static<br /> analysis tool.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 2.6.33 (including) 5.4.293 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.5 (including) 5.10.237 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.15.181 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 6.1.135 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.88 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.12.24 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.13.12 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.14 (including) 6.14.3 (excluding)
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*