cbcvebase.
CVE-2025-23160
published 2025-05-01

CVE-2025-23160: In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Fix a resource leak related to the scp device in FW initialization…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
8.8th percentile
In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Fix a resource leak related to the scp device in FW initialization On Mediatek devices with a system companion processor (SCP) the mtk_scp structure has to be removed explicitly to avoid a resource leak. Free the structure in case the allocation of the firmware structure fails during the firmware initialization.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.153-1 (bookworm)linux 6.1.153-1 (bookworm)
debianlinux-6.1< linux 6.1.153-1 (bookworm)linux 6.1.153-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 53dbe08504442dc7ba4865c09b3bbf5fe849681b < 9f009fa823c54ca0857c81f7525ea5a5d32de29c9f009fa823c54ca0857c81f7525ea5a5d32de29c
linuxlinux>= 53dbe08504442dc7ba4865c09b3bbf5fe849681b < d6cb086aa52bd51378a4c9e2b25d2def97770205d6cb086aa52bd51378a4c9e2b25d2def97770205
linuxlinux>= 53dbe08504442dc7ba4865c09b3bbf5fe849681b < ac94e1db4b2053059779472eb58a64d504964240ac94e1db4b2053059779472eb58a64d504964240
linuxlinux>= 53dbe08504442dc7ba4865c09b3bbf5fe849681b < 4936cd5817af35d23e4d283f48fa59a18ef481e44936cd5817af35d23e4d283f48fa59a18ef481e4
linuxlinux>= 6.1.130 < 6.1.1536.1.153
linuxlinux>= 6.6.36 < 6.6.886.6.88
linuxlinux>= 6.9.7 < 6.106.10
linuxlinux>= eeb62bb4ca22db17f7dfe8fb8472e0442df3d92f < 69dd5bbdd79c65445bb17c3c53510783bc1d756c69dd5bbdd79c65445bb17c3c53510783bc1d756c
linuxlinux>= f066882293b5ad359e44c4ed24ab1811ffb0b354 < fd7bb97ede487b9f075707b7408a9073e0d474b1fd7bb97ede487b9f075707b7408a9073e0d474b1
linuxlinux_kernel>= 0 < 6.1.153-16.1.153-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 6.1.130 < 6.1.1536.1.153
linuxlinux_kernel>= 6.13 < 6.13.126.13.12
linuxlinux_kernel>= 6.14 < 6.14.36.14.3
linuxlinux_kernel>= 6.6.36 < 6.6.886.6.88
linuxlinux_kernel>= 6.9.7 < 6.12.246.12.24
ubuntulinux-aws

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu3.2LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.