CVE-2025-38225

MEDIUM EPSS 3.5%
Published Jul 4, 202512mo ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Jul 4, 2025 12mo ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: media: imx-jpeg: Cleanup after an allocation error When allocation failures are not cleaned up by the driver, further allocation errors will be false-positives, which will cause buffers to remain uninitialized and cause NULL pointer dereferences. Ensure proper cleanup of failed allocations to prevent these issues.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
3.5% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-908

Affected Products 5

VendorProductVersionRange
linuxlinux_kernel*≥5.13  –  <6.1.143
linuxlinux_kernel*≥6.2  –  <6.6.95
linuxlinux_kernel*≥6.7  –  <6.12.35
linuxlinux_kernel*≥6.13  –  <6.15.4
debiandebian_linux11.0any

References 6

  • git.kernel.org https://git.kernel.org/stable/c/0ee9469f818a0b4de3c0e7aecd733c103820d181
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/6d0efe7d35c75394f32ff9d0650a007642d23857
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/7500bb9cf164edbb2c8117d57620227b1a4a8369
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b89ff9cf37ff59399f850d5f7781ef78fc37679f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ec26be7d6355a05552a0d0c1e73031f83aa4dc7f
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
    Mailing ListThird Party Advisory

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/0ee9469f818a0b4de3c0e7aecd733c103820d181
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/6d0efe7d35c75394f32ff9d0650a007642d23857
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/7500bb9cf164edbb2c8117d57620227b1a4a8369
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b89ff9cf37ff59399f850d5f7781ef78fc37679f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ec26be7d6355a05552a0d0c1e73031f83aa4dc7f
    Patch