CVE-2025-21976 (GCVE-0-2025-21976)
Vulnerability from cvelistv5
Published
2025-04-01 15:47
Modified
2026-08-05 11:55
Summary
In the Linux kernel, the following vulnerability has been resolved: fbdev: hyperv_fb: Allow graceful removal of framebuffer When a Hyper-V framebuffer device is unbind, hyperv_fb driver tries to release the framebuffer forcefully. If this framebuffer is in use it produce the following WARN and hence this framebuffer is never released. [ 44.111220] WARNING: CPU: 35 PID: 1882 at drivers/video/fbdev/core/fb_info.c:70 framebuffer_release+0x2c/0x40 < snip > [ 44.111289] Call Trace: [ 44.111290] <TASK> [ 44.111291] ? show_regs+0x6c/0x80 [ 44.111295] ? __warn+0x8d/0x150 [ 44.111298] ? framebuffer_release+0x2c/0x40 [ 44.111300] ? report_bug+0x182/0x1b0 [ 44.111303] ? handle_bug+0x6e/0xb0 [ 44.111306] ? exc_invalid_op+0x18/0x80 [ 44.111308] ? asm_exc_invalid_op+0x1b/0x20 [ 44.111311] ? framebuffer_release+0x2c/0x40 [ 44.111313] ? hvfb_remove+0x86/0xa0 [hyperv_fb] [ 44.111315] vmbus_remove+0x24/0x40 [hv_vmbus] [ 44.111323] device_remove+0x40/0x80 [ 44.111325] device_release_driver_internal+0x20b/0x270 [ 44.111327] ? bus_find_device+0xb3/0xf0 Fix this by moving the release of framebuffer and assosiated memory to fb_ops.fb_destroy function, so that framebuffer framework handles it gracefully. While we fix this, also replace manual registrations/unregistration of framebuffer with devm_register_framebuffer.
Impacted products
Vendor Product Version
Linux Linux Version: 68a2d20b79b105f02dcbc52c211d7e62f98996b7
Version: 68a2d20b79b105f02dcbc52c211d7e62f98996b7
Version: 68a2d20b79b105f02dcbc52c211d7e62f98996b7
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/video/fbdev/hyperv_fb.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "4545e2aa121aea304d33903099c03e29ed4fe50a",
              "status": "affected",
              "version": "68a2d20b79b105f02dcbc52c211d7e62f98996b7",
              "versionType": "git"
            },
            {
              "lessThan": "a7b583dc99c6cf4a96877017be1d08247e1ef2c7",
              "status": "affected",
              "version": "68a2d20b79b105f02dcbc52c211d7e62f98996b7",
              "versionType": "git"
            },
            {
              "lessThan": "ea2f45ab0e53b255f72c85ccd99e2b394fc5fceb",
              "status": "affected",
              "version": "68a2d20b79b105f02dcbc52c211d7e62f98996b7",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/video/fbdev/hyperv_fb.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.10"
            },
            {
              "lessThan": "3.10",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.20",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.13.*",
              "status": "unaffected",
              "version": "6.13.8",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.14",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.20",
                  "versionStartIncluding": "3.10",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.13.8",
                  "versionStartIncluding": "3.10",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.14",
                  "versionStartIncluding": "3.10",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: hyperv_fb: Allow graceful removal of framebuffer\n\nWhen a Hyper-V framebuffer device is unbind, hyperv_fb driver tries to\nrelease the framebuffer forcefully. If this framebuffer is in use it\nproduce the following WARN and hence this framebuffer is never released.\n\n[   44.111220] WARNING: CPU: 35 PID: 1882 at drivers/video/fbdev/core/fb_info.c:70 framebuffer_release+0x2c/0x40\n\u003c snip \u003e\n[   44.111289] Call Trace:\n[   44.111290]  \u003cTASK\u003e\n[   44.111291]  ? show_regs+0x6c/0x80\n[   44.111295]  ? __warn+0x8d/0x150\n[   44.111298]  ? framebuffer_release+0x2c/0x40\n[   44.111300]  ? report_bug+0x182/0x1b0\n[   44.111303]  ? handle_bug+0x6e/0xb0\n[   44.111306]  ? exc_invalid_op+0x18/0x80\n[   44.111308]  ? asm_exc_invalid_op+0x1b/0x20\n[   44.111311]  ? framebuffer_release+0x2c/0x40\n[   44.111313]  ? hvfb_remove+0x86/0xa0 [hyperv_fb]\n[   44.111315]  vmbus_remove+0x24/0x40 [hv_vmbus]\n[   44.111323]  device_remove+0x40/0x80\n[   44.111325]  device_release_driver_internal+0x20b/0x270\n[   44.111327]  ? bus_find_device+0xb3/0xf0\n\nFix this by moving the release of framebuffer and assosiated memory\nto fb_ops.fb_destroy function, so that framebuffer framework handles\nit gracefully.\n\nWhile we fix this, also replace manual registrations/unregistration of\nframebuffer with devm_register_framebuffer."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerability is reached through local interfaces only \u2014 opening and mmap\u0027ing the `/dev/fbN` character device and the local/administrative device-removal path (sysfs unbind, module unload, or VMBus rescind of the guest\u0027s synthetic video device). No network or adjacent-network vector exists for hyperv_fb.\nAC:L - There is no race to win: a process simply holds an mmap of `/dev/fb0`, and the premature `vfree()`/`kvfree()` in `hvfb_remove()` deterministically leaves that mapping and the `info-\u003epagerefs` array pointing at freed memory. Grooming the recycled pages afterwards is under the attacker\u0027s control via ordinary allocation pressure.\nPR:L - The party that gains the freed-memory read/write primitive only needs to open and mmap the framebuffer device, which unprivileged seat/console users (logind ACLs), `video`-group members, and graphics-domain processes on embedded/Android-style systems routinely can do. No CAP_SYS_ADMIN is needed to hold the mapping that survives the teardown.\nUI:N - The removal that triggers the free is a device/administrative event \u2014 Hyper-V host-side rescind of the video VMBus device, driver reload during a package update, or automated unbind \u2014 not an action by a victim user, and the attacking process merely has to be mapped when it occurs. This matches the treatment of the identical fbdev hot-unplug-while-mapped class.\nS:U - The corrupted resources (vmalloc pages, the deferred-I/O pageref array, the leaked `fb_info`) are all kernel memory managed by the same security authority as the vulnerable driver. No hypervisor, IOMMU, or sandbox boundary is crossed.\nC:H - After `vfree(par-\u003edio_vp)` the surviving userspace mapping still points at pages handed back to the page allocator, so the attacker can read whatever kernel data those pages are subsequently reused for \u2014 slab objects, page tables, credentials \u2014 an effectively arbitrary kernel memory disclosure.\nI:H - The same surviving mapping is writable, giving a page-granularity write primitive into recycled kernel memory, and write faults additionally corrupt the kvfree\u0027d `info-\u003epagerefs` array and lock a destroyed mutex. That combination is a classic path to heap/page-table corruption and control-flow hijack.\nA:H - Unbind with the framebuffer in use produces a `WARN_ON` in `framebuffer_release()` (fatal under panic_on_warn) plus an `fb_info` leak, and subsequent access from the still-open fd faults on freed vmalloc memory, walks a freed pageref array, and locks a destroyed mutex \u2014 resulting in oops/panic."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:55:48.624Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/4545e2aa121aea304d33903099c03e29ed4fe50a"
        },
        {
          "url": "https://git.kernel.org/stable/c/a7b583dc99c6cf4a96877017be1d08247e1ef2c7"
        },
        {
          "url": "https://git.kernel.org/stable/c/ea2f45ab0e53b255f72c85ccd99e2b394fc5fceb"
        }
      ],
      "title": "fbdev: hyperv_fb: Allow graceful removal of framebuffer",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2025-21976",
    "datePublished": "2025-04-01T15:47:07.120Z",
    "dateReserved": "2024-12-29T08:45:45.798Z",
    "dateUpdated": "2026-08-05T11:55:48.624Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…