« List of all CVEs

CVE-2025-23160

media: mediatek: vcodec: Fix a resource leak related to the scp device in FW initialization

Published: 5/1/2025 Last updated: 11/3/2025 Reserved: 1/11/2025

In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Fix a resource leak related to the scp device in FW initialization On Mediatek devices with a system companion processor (SCP) the mtk_scp structure has to be removed explicitly to avoid a resource leak. Free the structure in case the allocation of the firmware structure fails during the firmware initialization.

CNA assigner: Linux (416baaa9-dc9f-4396-8d5f-8c081fb06d67) Requested by: n/a

Opam packages affected (27)

albatross cdrom conf-bpftool conf-libbpf conf-linux-libc-dev core core_unix hvsock mirage-block-unix mm ocaml-probes orun rawlink rawlink-eio rawlink-lwt shell solo5 solo5-bindings-hvt solo5-bindings-spt solo5-cross-aarch64 solo5-kernel-ukvm tracy-client tuntap uring vhd-format vhd-format-lwt xapi-stdext-unix

Products affected (4)

Product Vendor Version
Linux Linux all IPA 4.7.x versions before 4.7.4
Linux Linux all IPa 4.8.x versions before 4.8.3
Linux Linux 10.5(1)SU2
Linux Linux < 16.2R1-S6, 16.2R2-S5, 16.2R3

References (14)