CVE-2025-38630 | Linux Kernel up to 6.1.147/6.6.101/6.12.41/6.15.9/6.16.0 fbdev fb_add_videomode return null pointer dereference (Nessus ID 276629 / WID-SEC-2025-1898)
A vulnerability was found in Linux Kernel up to 6.1.147/6.6.101/6.12.41/6.15.9/6.16.0. It has been classified as critical. This affects the function fb_add_videomode of the component fbdev. Performing a manipulation of the argument return results in null pointer dereference.
This vulnerability is identified as CVE-2025-38630. The attack can only be performed from the local network. There is not any exploit available.
Upgrading the affected component is recommended.