CVE-2025-38225

In the Linux kernel, the following vulnerability has been resolved: media: imx-jpeg: Cleanup after an allocation error When allocation failures are not cleaned up by the driver, further allocation errors will be false-positives, which will cause buffers to remain uninitialized and cause NULL pointer dereferences. Ensure proper cleanup of failed allocations to prevent these issues.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

History

18 Dec 2025, 19:46

Type Values Removed Values Added
CWE CWE-908
First Time Linux
Debian
Debian debian Linux
Linux linux Kernel
CPE cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
References () https://git.kernel.org/stable/c/0ee9469f818a0b4de3c0e7aecd733c103820d181 - () https://git.kernel.org/stable/c/0ee9469f818a0b4de3c0e7aecd733c103820d181 - Patch
References () https://git.kernel.org/stable/c/6d0efe7d35c75394f32ff9d0650a007642d23857 - () https://git.kernel.org/stable/c/6d0efe7d35c75394f32ff9d0650a007642d23857 - Patch
References () https://git.kernel.org/stable/c/7500bb9cf164edbb2c8117d57620227b1a4a8369 - () https://git.kernel.org/stable/c/7500bb9cf164edbb2c8117d57620227b1a4a8369 - Patch
References () https://git.kernel.org/stable/c/b89ff9cf37ff59399f850d5f7781ef78fc37679f - () https://git.kernel.org/stable/c/b89ff9cf37ff59399f850d5f7781ef78fc37679f - Patch
References () https://git.kernel.org/stable/c/ec26be7d6355a05552a0d0c1e73031f83aa4dc7f - () https://git.kernel.org/stable/c/ec26be7d6355a05552a0d0c1e73031f83aa4dc7f - Patch
References () https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html - () https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html - Third Party Advisory, Mailing List

03 Nov 2025, 18:16

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html -

08 Jul 2025, 16:18

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: media: imx-jpeg: Limpieza tras un error de asignación. Si el controlador no corrige los fallos de asignación, los errores de asignación posteriores serán falsos positivos, lo que provocará que los búferes permanezcan sin inicializar y desreferencias de punteros nulos. Asegúrese de que las asignaciones fallidas se limpien correctamente para evitar estos problemas.

06 Jul 2025, 10:15

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/b89ff9cf37ff59399f850d5f7781ef78fc37679f -

04 Jul 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-04 14:15

Updated : 2025-12-18 19:46


NVD link : CVE-2025-38225

Mitre link : CVE-2025-38225

CVE.ORG link : CVE-2025-38225


JSON object : View

Products Affected

debian

  • debian_linux

linux

  • linux_kernel
CWE
CWE-908

Use of Uninitialized Resource