CVE-2025-40304

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/12/2025
Last modified:
08/12/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> fbdev: Add bounds checking in bit_putcs to fix vmalloc-out-of-bounds<br /> <br /> Add bounds checking to prevent writes past framebuffer boundaries when<br /> rendering text near screen edges. Return early if the Y position is off-screen<br /> and clip image height to screen boundary. Break from the rendering loop if the<br /> X position is off-screen. When clipping image width to fit the screen, update<br /> the character count to match the clipped width to prevent buffer size<br /> mismatches.<br /> <br /> Without the character count update, bit_putcs_aligned and bit_putcs_unaligned<br /> receive mismatched parameters where the buffer is allocated for the clipped<br /> width but cnt reflects the original larger count, causing out-of-bounds writes.

Impact