CVE-2025-23160

In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Fix a resource leak related to the scp device in FW initialization On Mediatek devices with a system companion processor (SCP) the mtk_scp structure has to be removed explicitly to avoid a resource leak. Free the structure in case the allocation of the firmware structure fails during the firmware initialization.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

History

06 Nov 2025, 21:32

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
References () https://git.kernel.org/stable/c/4936cd5817af35d23e4d283f48fa59a18ef481e4 - () https://git.kernel.org/stable/c/4936cd5817af35d23e4d283f48fa59a18ef481e4 - Patch
References () https://git.kernel.org/stable/c/69dd5bbdd79c65445bb17c3c53510783bc1d756c - () https://git.kernel.org/stable/c/69dd5bbdd79c65445bb17c3c53510783bc1d756c - Patch
References () https://git.kernel.org/stable/c/9f009fa823c54ca0857c81f7525ea5a5d32de29c - () https://git.kernel.org/stable/c/9f009fa823c54ca0857c81f7525ea5a5d32de29c - Patch
References () https://git.kernel.org/stable/c/ac94e1db4b2053059779472eb58a64d504964240 - () https://git.kernel.org/stable/c/ac94e1db4b2053059779472eb58a64d504964240 - Patch
References () https://git.kernel.org/stable/c/d6cb086aa52bd51378a4c9e2b25d2def97770205 - () https://git.kernel.org/stable/c/d6cb086aa52bd51378a4c9e2b25d2def97770205 - Patch
References () https://git.kernel.org/stable/c/fd7bb97ede487b9f075707b7408a9073e0d474b1 - () https://git.kernel.org/stable/c/fd7bb97ede487b9f075707b7408a9073e0d474b1 - Patch
References () https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html - () https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html - Third Party Advisory
First Time Debian debian Linux
Linux
Debian
Linux linux Kernel
CWE CWE-401

03 Nov 2025, 18:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html -

19 Sep 2025, 15:15

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/69dd5bbdd79c65445bb17c3c53510783bc1d756c -
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: media: mediatek: vcodec: Se corrige una fuga de recursos relacionada con el dispositivo scp durante la inicialización del firmware. En dispositivos Mediatek con un procesador complementario del sistema (SCP), la estructura mtk_scp debe eliminarse explícitamente para evitar una fuga de recursos. Libere la estructura en caso de que la asignación de la estructura del firmware falle durante la inicialización.

01 May 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-01 13:15

Updated : 2025-11-06 21:32


NVD link : CVE-2025-23160

Mitre link : CVE-2025-23160

CVE.ORG link : CVE-2025-23160


JSON object : View

Products Affected

debian

  • debian_linux

linux

  • linux_kernel
CWE
CWE-401

Missing Release of Memory after Effective Lifetime