CVE-2025-40207

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/11/2025
Last modified:
12/11/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> media: v4l2-subdev: Fix alloc failure check in v4l2_subdev_call_state_try()<br /> <br /> v4l2_subdev_call_state_try() macro allocates a subdev state with<br /> __v4l2_subdev_state_alloc(), but does not check the returned value. If<br /> __v4l2_subdev_state_alloc fails, it returns an ERR_PTR, and that would<br /> cause v4l2_subdev_call_state_try() to crash.<br /> <br /> Add proper error handling to v4l2_subdev_call_state_try().

Impact