NONE · 0

CVE-2025-40207

In the Linux kernel, the following vulnerability has been resolved: media: v4l2-subdev: Fix alloc failure check in v4l2_subdev_call_state_try() v4l2_subdev_call_state_try() macro allocates a subdev ...

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: media: v4l2-subdev: Fix alloc failure check in v4l2_subdev_call_state_try() v4l2_subdev_call_state_try() macro allocates a subdev state with __v4l2_subdev_state_alloc(), but does not check the returned value. If __v4l2_subdev_state_alloc fails, it returns an ERR_PTR, and that would cause v4l2_subdev_call_state_try() to crash. Add proper error handling to v4l2_subdev_call_state_try().

References

FAQ

What is CVE-2025-40207?

CVE-2025-40207 is a documented vulnerability. In the Linux kernel, the following vulnerability has been resolved: media: v4l2-subdev: Fix alloc failure check in v4l2_subdev_call_state_try() v4l2_subdev_call_state_try() macro allocates a subdev ...

How severe is CVE-2025-40207?

CVSS scoring is not yet available for CVE-2025-40207. Check NVD for updates.

Is there a patch for CVE-2025-40207?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.