Review reviewHigh

CVE-2025-38685

Linux Linux, SIMATIC CN 4100, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP

In the Linux kernel, the following vulnerability has been resolved: fbdev: Fix vmalloc out-of-bounds write in fast_imageblit This issue triggers when a userspace program does an ioctl FBIOPUT_CON2FBMAP by passing console number and frame buffer number. Ideally this maps console to frame buffer and updates the screen if console is visible. As part of mapping it has to do resize of console according to frame buffer info. if this resize fails and returns from vc_do_resize() and continues further. At this point console and new frame buffer are mapped and sets display vars. Despite failure still...

CVSS
7.8
EPSS
0.17%
6.98% percentile
CISA KEV
Not listed
Published
2025.09.05
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.17%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: fbdev: Fix vmalloc out-of-bounds write in fast_imageblit This issue triggers when a userspace program does an ioctl FBIOPUT_CON2FBMAP by passing console number and frame buffer number. Ideally this maps console to frame buffer and updates the screen if console is visible. As part of mapping it has to do resize of console according to frame buffer info. if this resize fails and returns from vc_do_resize() and continues further. At this point console and new frame buffer are mapped and sets display vars. Despite failure still...

Affected product and versions

Product
Linux Linux, SIMATIC CN 4100, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP
Affected versions
>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 078e62bffca4b7e72e8f3550eb063ab981c36c7a, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 4c4d7ddaf1d43780b106bedc692679f965dc5a3a, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 27b118aebdd84161c8ff5ce49d9d536f2af10754, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < ed9b8e5016230868c8d813d9179523f729fec8c6, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 56701bf9eeb63219e378cb7fcbd066ea4eaeeb50, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < cfec17721265e72e50cc69c6004fe3475cd38df2, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < af0db3c1f898144846d4c172531a199bb3ca375d, >= 2.6.12, < V5.0, >= V3.1.5, >= 2.6.13 < 5.15.190, >= 5.16 < 6.1.149, >= 6.2 < 6.6.103, >= 6.7 < 6.12.43, >= 6.13 < 6.15.11, >= 6.16 < 6.16.2, 2.6.12, 11.0
Fixed versions
5.15.190, 6.1.149, 6.6.103, 6.12.43, 6.15.11, 6.16.2

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, SIMATIC CN 4100, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-787
CVE-2025-38685 — Linux Linux, SIMATIC CN 4100, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP | SECUFOCUS NOW