CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2024-49925: fbdev: efifb: Register sysfs groups through driver core

mediumCVSS 5.5CVE-2024-49925

CSIRTS triage

What
The EFI framebuffer driver registers sysfs groups without proper driver core integration, potentially exposing uninitialized or sensitive memory.
Who is affected
Systems with EFI firmware and efifb graphics driver enabled.
Urgency
Medium severity with CVSS 5.5; potential information disclosure of kernel memory.
Action
Update the Linux kernel to register efifb sysfs groups through the driver core properly.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Linux kernel efifb driver

Get an email when a new Linux kernel efifb driver advisory drops — max one per day, one-click unsubscribe.

Details

Source
Microsoft Security Response Center (INTL · vendor-psirt · site)
Severity
medium — CVSS 5.5
Published
2026-08-06
Exploitation
Not in CISA KEV at last sync

Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49925

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2024-49925coverage & exploitation statusNVD · CVE.org

More from Microsoft Security Response Center