Answer in brief
CVE-2025-38080 records a Unknown severity vulnerability in drm/amd/display: Increase block_sequence array size. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c <de67e80ab48f1f23663831007a2fa3c1471a7757 || >=4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c <e55c5704b12eeea27e212bfab8f7e51ad3e8ac1f || >=4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c <bf1666072e7482317cf2302621766482a21a62c7 || >=4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c <3a7810c212bcf2f722671dadf4b23ff70a7d23ee | de67e80ab48f1f23663831007a2fa3c1471a7757, e55c5704b12eeea27e212bfab8f7e51ad3e8ac1f, bf1666072e7482317cf2302621766482a21a62c7, 3a7810c212bcf2f722671dadf4b23ff70a7d23ee |
| Linux/Linuxgeneric | 4.15 | Not reported |
Published upstream
Jun 18, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Increase block_sequence array size [Why] It's possible to generate more than 50 steps in hwss_build_fast_sequence, for example with a 6-pipe asic where all pipes are in one MPC chain. This overflows the block_sequence buffer and corrupts block_sequence_steps, causing a crash. [How] Expand block_sequence to 100 items. A naive upper bound on the possible number of steps for a 6-pipe asic, ignoring the potential for steps to be mutually exclusive, is 91 with current code, therefore 100 is sufficient.
Quoted source text, attributed separately from HOL analysis.