cbcvebase.
CVE-2025-38427
published 2025-07-25

CVE-2025-38427: In the Linux kernel, the following vulnerability has been resolved: video: screen_info: Relocate framebuffers behind PCI bridges Apply PCI host-bridge window…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
5.2th percentile
In the Linux kernel, the following vulnerability has been resolved: video: screen_info: Relocate framebuffers behind PCI bridges Apply PCI host-bridge window offsets to screen_info framebuffers. Fixes invalid access to I/O memory. Resources behind a PCI host bridge can be relocated by a certain offset in the kernel's CPU address range used for I/O. The framebuffer memory range stored in screen_info refers to the CPU addresses as seen during boot (where the offset is 0). During boot up, firmware may assign a different memory offset to the PCI host bridge and thereby relocating the framebuffer address of the PCI graphics device as seen by the kernel. The information in screen_info must be updated as well. The helper pcibios_bus_to_resource() performs the relocation of the screen_info's framebuffer resource (given in PCI bus addresses). The result matches the I/O-memory resource of the PCI graphics device (given in CPU addresses). As before, we store away the information necessary to later update the information in screen_info itself. Commit 78aa89d1dfba ("firmware/sysfb: Update screen_info for relocated EFI framebuffers") added the code for updating screen_info. It is based on similar functionality that pre-existed in efifb. Efifb uses a pointer to the PCI resource, while the newer code does a memcpy of the region. Hence efifb sees any updates to the PCI resource and avoids the issue. v3: - Only use struct pci_bus_region for PCI bus addresses (Bjorn) - Clarify address semantics in commit messages and comments (Bjorn) v2: - Fixed tags (Takashi, Ivan) - Updated information on efifb

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.35-1 (forky)linux 6.12.35-1 (forky)
linuxlinux
linuxlinux>= 6.6.45 < 6.6.956.6.95
linuxlinux>= 78aa89d1dfba1e3cf4a2e053afa3b4c4ec622371 < 5c70e3ad85d2890d8af375333699429de26327f25c70e3ad85d2890d8af375333699429de26327f2
linuxlinux>= 78aa89d1dfba1e3cf4a2e053afa3b4c4ec622371 < aeda386d86d79269a08f470dbdc53d13a91e51faaeda386d86d79269a08f470dbdc53d13a91e51fa
linuxlinux>= 78aa89d1dfba1e3cf4a2e053afa3b4c4ec622371 < 2f29b5c231011b94007d2c8a6d793992f2275db12f29b5c231011b94007d2c8a6d793992f2275db1
linuxlinux>= a168da3182f8727b338509cb413147aa29012d6f < cc3cc41ed67054a03134bea42408c720eec0fa04cc3cc41ed67054a03134bea42408c720eec0fa04
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 6.13 < 6.15.46.15.4
linuxlinux_kernel>= 6.6.45 < 6.6.956.6.95
linuxlinux_kernel>= 6.9 < 6.12.356.12.35
msrccbl2_kernel_5.15.122.1-2_on_cbl_mariner_2.0
msrccm1_kernel_5.10.188.1-1_on_cbl_mariner_1.0
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-gkeop
ubuntulinux-nvidia
ubuntulinux-nvidia-6.8
ubuntulinux-oracle
ubuntulinux-oracle-6.8
ubuntulinux-raspi-realtime
ubuntulinux-realtime

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.6MEDIUM
vendor_msrc9.8CRITICAL
vendor_ubuntu5.6MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.