CVE-2025-40197
published 2025-11-12CVE-2025-40197: In the Linux kernel, the following vulnerability has been resolved: media: mc: Clear minor number before put device The device minor should not be cleared…
PriorityP420medium5.5
EPSS
0.19%
9.5th percentile
In the Linux kernel, the following vulnerability has been resolved:
media: mc: Clear minor number before put device
The device minor should not be cleared after the device is released.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.158-1 (bookworm) | linux 6.1.158-1 (bookworm) |
| debian | linux-6.1 | < linux 6.1.158-1 (bookworm) | linux 6.1.158-1 (bookworm) |
| linux | linux | < 5.4.301 | 5.4.301 |
| linux | linux | < 5.10.246 | 5.10.246 |
| linux | linux | < 5.15.195 | 5.15.195 |
| linux | linux | < 6.1.157 | 6.1.157 |
| linux | linux | < 6.6.113 | 6.6.113 |
| linux | linux | < 6.12.54 | 6.12.54 |
| linux | linux | < 6.17.4 | 6.17.4 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < dd156f44ea82cc249f46c519eed3b2f8983c8002 | dd156f44ea82cc249f46c519eed3b2f8983c8002 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 64dbc6f50ce92b7da203b1bcdd96a370bbc9b74d | 64dbc6f50ce92b7da203b1bcdd96a370bbc9b74d |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 5d327391f9fafeb0938be4fc538dd0bd54a0b2ef | 5d327391f9fafeb0938be4fc538dd0bd54a0b2ef |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 8f52c7f38f0f2ee2afc331e6b873acba5e9490a8 | 8f52c7f38f0f2ee2afc331e6b873acba5e9490a8 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7bd4e5367d0940ccec4d7546bb6bd019ab2c71aa | 7bd4e5367d0940ccec4d7546bb6bd019ab2c71aa |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7db47e737128b3585ae679b709b85f3f44cd8750 | 7db47e737128b3585ae679b709b85f3f44cd8750 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < ac01416d477c2dc6016782635ae022f8cc634a29 | ac01416d477c2dc6016782635ae022f8cc634a29 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 8cfc8cec1b4da88a47c243a11f384baefd092a50 | 8cfc8cec1b4da88a47c243a11f384baefd092a50 |
| linux | linux_kernel | >= 0 < 5.10.247-1 | 5.10.247-1 |
| linux | linux_kernel | >= 0 < 6.1.158-1 | 6.1.158-1 |
| linux | linux_kernel | >= 0 < 6.12.57-1 | 6.12.57-1 |
| linux | linux_kernel | >= 0 < 6.17.6-1 | 6.17.6-1 |
| linux | linux_kernel | >= 0 < 5.4.301 | 5.4.301 |
| linux | linux_kernel | >= 5.11.0 < 5.15.195 | 5.15.195 |
| linux | linux_kernel | >= 5.16.0 < 6.1.157 | 6.1.157 |
| linux | linux_kernel | >= 5.5.0 < 5.10.246 | 5.10.246 |
CVSS provenance
vendor_msrc5.5MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qcmj-qqpx-xfgc: In the Linux kernel, the following vulnerability has been resolved:
media: mc: Clear minor number before put device
The device minor should not be c
ghsa_unreviewed·2025-11-13
CVE-2025-40197 GHSA-qcmj-qqpx-xfgc: In the Linux kernel, the following vulnerability has been resolved:
media: mc: Clear minor number before put device
The device minor should not be c
In the Linux kernel, the following vulnerability has been resolved:
media: mc: Clear minor number before put device
The device minor should not be cleared after the device is released.
OSV
media: mc: Clear minor number before put device
osv·2025-11-12
CVE-2025-40197 media: mc: Clear minor number before put device
media: mc: Clear minor number before put device
In the Linux kernel, the following vulnerability has been resolved:
media: mc: Clear minor number before put device
The device minor should not be cleared after the device is released.
OSV
CVE-2025-40197: In the Linux kernel, the following vulnerability has been resolved: media: mc: Clear minor number before put device The device minor should not be cle
osv·2025-11-12
CVE-2025-40197 CVE-2025-40197: In the Linux kernel, the following vulnerability has been resolved: media: mc: Clear minor number before put device The device minor should not be cle
In the Linux kernel, the following vulnerability has been resolved: media: mc: Clear minor number before put device The device minor should not be cleared after the device is released.
Red Hat
kernel: media: mc: Clear minor number before put device
vendor_redhat·2025-11-12·CVSS 4.7
CVE-2025-40197 [MEDIUM] CWE-908 kernel: media: mc: Clear minor number before put device
kernel: media: mc: Clear minor number before put device
In the Linux kernel, the following vulnerability has been resolved:
media: mc: Clear minor number before put device
The device minor should not be cleared after the device is released.
A flaw was found in the Linux kernel’s media controller (“mc”) subsystem: the code incorrectly clears the device minor number when media_devnode_release() / media_devnode_unregister() is called, even though the device is already released
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: kernel (Red Hat Enterprise Linux 10) - Affected
Package: kerne
Microsoft
media: mc: Clear minor number before put device
vendor_msrc·2025-11-11·CVSS 5.5
CVE-2025-40197 [MEDIUM] media: mc: Clear minor number before put device
media: mc: Clear minor number before put device
Mariner: Mariner
Linux: Linux
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Debian
CVE-2025-40197: linux - In the Linux kernel, the following vulnerability has been resolved: media: mc: ...
vendor_debian·2025
CVE-2025-40197 CVE-2025-40197: linux - In the Linux kernel, the following vulnerability has been resolved: media: mc: ...
In the Linux kernel, the following vulnerability has been resolved: media: mc: Clear minor number before put device The device minor should not be cleared after the device is released.
Scope: local
bookworm: resolved (fixed in 6.1.158-1)
bullseye: resolved (fixed in 5.10.247-1)
forky: resolved (fixed in 6.17.6-1)
sid: resolved (fixed in 6.17.6-1)
trixie: resolved (fixed in 6.12.57-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/5d327391f9fafeb0938be4fc538dd0bd54a0b2efhttps://git.kernel.org/stable/c/64dbc6f50ce92b7da203b1bcdd96a370bbc9b74dhttps://git.kernel.org/stable/c/7bd4e5367d0940ccec4d7546bb6bd019ab2c71aahttps://git.kernel.org/stable/c/7db47e737128b3585ae679b709b85f3f44cd8750https://git.kernel.org/stable/c/8cfc8cec1b4da88a47c243a11f384baefd092a50https://git.kernel.org/stable/c/8f52c7f38f0f2ee2afc331e6b873acba5e9490a8https://git.kernel.org/stable/c/ac01416d477c2dc6016782635ae022f8cc634a29https://git.kernel.org/stable/c/dd156f44ea82cc249f46c519eed3b2f8983c8002
2025-11-12
Published