CVE-2025-40197 — Use of Uninitialized Resource in Linux
Severity
4.7MEDIUM
No vectorEPSS
0.0%
top 87.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 12
Latest updateNov 13
Description
In the Linux kernel, the following vulnerability has been resolved:
media: mc: Clear minor number before put device
The device minor should not be cleared after the device is released.
Affected Packages6 packages
▶CVEListV5linux/linux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 — dd156f44ea82cc249f46c519eed3b2f8983c8002+7
🔴Vulnerability Details
3GHSA▶
GHSA-qcmj-qqpx-xfgc: In the Linux kernel, the following vulnerability has been resolved:
media: mc: Clear minor number before put device
The device minor should not be c↗2025-11-13
OSV▶
CVE-2025-40197: In the Linux kernel, the following vulnerability has been resolved: media: mc: Clear minor number before put device The device minor should not be cle↗2025-11-12