ThreatCluster

Microsoft Fixes Null Pointer Dereference Vulnerabilities in fbdev

First seen 18 Feb 2026, 12:23 UTC Api.Msrc.Microsoft 39

Article Content

Browse articles
ThreatCluster

Microsoft has published information regarding two vulnerabilities in the fbdev subsystem, identified as CVE-2025-38214 and CVE-2025-38215. Both vulnerabilities involve null pointer dereference issues in the fb_videomode_to_var function, which could potentially lead to system instability. The vulnerabilities were published on July 4, 2025, and have now been addressed with fixes.

Timeline

2025-07-04
CVE-2025-38214 published
2025-07-04
CVE-2025-38215 published
2026-02-18
Information published about the fixes for both CVEs