In the Linux kernel, the following vulnerability has been resolved:
fbdev: fix potential buffer overflow in doregisterframebuffer()
The current implementation may lead to buffer overflow when: 1. Unregistration creates NULL gaps in registeredfb[] 2. All array slots become occupied despite numregisteredfb < FBMAX 3. The registration loop exceeds array bounds
Add boundary check to prevent registeredfb[FBMAX] access.