In the Linux kernel, the following vulnerability has been resolved:
media: vimc: skip .s_stream() for stopped entities
Syzbot reported [1] a warning prompted by a check in callsstream() that checks whether .s_stream() operation is warranted for unstarted or stopped subdevs.
Add a simple fix in vimcstreamerpipelineterminate() ensuring that entities skip a call to .sstream() unless they have been previously properly started.
[1] Syzbot report: ------------[ cut here ]------------ WARNING: CPU: 0 PID: 5933 at drivers/media/v4l2-core/v4l2-subdev.c:460 callsstream+0x2df/0x350 drivers/media/v4l2-core/v4l2-subdev.c:460 Modules linked in: CPU: 0 UID: 0 PID: 5933 Comm: syz-executor330 Not tainted 6.13.0-rc2-syzkaller-00362-g2d8308bf5b67 #0 ... Call Trace: <TASK> vimcstreamerpipelineterminate+0x218/0x320 drivers/media/test-drivers/vimc/vimc-streamer.c:62 vimcstreamerpipelineinit drivers/media/test-drivers/vimc/vimc-streamer.c:101 [inline] vimcstreamersstream+0x650/0x9a0 drivers/media/test-drivers/vimc/vimc-streamer.c:203 vimccapturestartstreaming+0xa1/0x130 drivers/media/test-drivers/vimc/vimc-capture.c:256 vb2startstreaming+0x15f/0x5a0 drivers/media/common/videobuf2/videobuf2-core.c:1789 vb2corestreamon+0x2a7/0x450 drivers/media/common/videobuf2/videobuf2-core.c:2348 vb2streamon drivers/media/common/videobuf2/videobuf2-v4l2.c:875 [inline] vb2ioctlstreamon+0xf4/0x170 drivers/media/common/videobuf2/videobuf2-v4l2.c:1118 _videodoioctl+0xaf0/0xf00 drivers/media/v4l2-core/v4l2-ioctl.c:3122 videousercopy+0x4d2/0x1620 drivers/media/v4l2-core/v4l2-ioctl.c:3463 v4l2ioctl+0x1ba/0x250 drivers/media/v4l2-core/v4l2-dev.c:366 vfsioctl fs/ioctl.c:51 [inline] _dosysioctl fs/ioctl.c:906 [inline] _sesysioctl fs/ioctl.c:892 [inline] _x64sysioctl+0x190/0x200 fs/ioctl.c:892 dosyscallx64 arch/x86/entry/common.c:52 [inline] dosyscall64+0xcd/0x250 arch/x86/entry/common.c:83 entrySYSCALL64afterhwframe+0x77/0x7f RIP: 0033:0x7f2b85c01b19 ...
[
{
"deprecated": false,
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"187964675120121735367084158501621918160",
"72020918560712982789959621135173119824",
"5735071825308482674844104372635310174",
"125922966049075630553949817963395470074"
]
},
"id": "CVE-2025-22028-135942e1",
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@6f6064dab4dcfb7e34a395040a0c9dc22cc8765d",
"target": {
"file": "drivers/media/test-drivers/vimc/vimc-streamer.c"
}
},
{
"deprecated": false,
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"187964675120121735367084158501621918160",
"72020918560712982789959621135173119824",
"5735071825308482674844104372635310174",
"125922966049075630553949817963395470074"
]
},
"id": "CVE-2025-22028-1f1ad480",
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a505075730d23ccc19fc4ac382a0ed73b630c057",
"target": {
"file": "drivers/media/test-drivers/vimc/vimc-streamer.c"
}
},
{
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 353.0,
"function_hash": "150396924922414040961000058668502494337"
},
"id": "CVE-2025-22028-237eacd7",
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@845e9286ff99ee88cfdeb2b748f730003a512190",
"target": {
"file": "drivers/media/test-drivers/vimc/vimc-streamer.c",
"function": "vimc_streamer_pipeline_terminate"
}
},
{
"deprecated": false,
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"187964675120121735367084158501621918160",
"72020918560712982789959621135173119824",
"5735071825308482674844104372635310174",
"125922966049075630553949817963395470074"
]
},
"id": "CVE-2025-22028-614eb641",
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@845e9286ff99ee88cfdeb2b748f730003a512190",
"target": {
"file": "drivers/media/test-drivers/vimc/vimc-streamer.c"
}
},
{
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 353.0,
"function_hash": "150396924922414040961000058668502494337"
},
"id": "CVE-2025-22028-a413b140",
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@6f6064dab4dcfb7e34a395040a0c9dc22cc8765d",
"target": {
"file": "drivers/media/test-drivers/vimc/vimc-streamer.c",
"function": "vimc_streamer_pipeline_terminate"
}
},
{
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 353.0,
"function_hash": "150396924922414040961000058668502494337"
},
"id": "CVE-2025-22028-b9a07d5c",
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7a58d4c4cf8ff60ab1f93399deefaf6057da91c7",
"target": {
"file": "drivers/media/test-drivers/vimc/vimc-streamer.c",
"function": "vimc_streamer_pipeline_terminate"
}
},
{
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 353.0,
"function_hash": "150396924922414040961000058668502494337"
},
"id": "CVE-2025-22028-bb81dd1f",
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@36cef585e2a31e4ddf33a004b0584a7a572246de",
"target": {
"file": "drivers/media/test-drivers/vimc/vimc-streamer.c",
"function": "vimc_streamer_pipeline_terminate"
}
},
{
"deprecated": false,
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"187964675120121735367084158501621918160",
"72020918560712982789959621135173119824",
"5735071825308482674844104372635310174",
"125922966049075630553949817963395470074"
]
},
"id": "CVE-2025-22028-bc3892cd",
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@36cef585e2a31e4ddf33a004b0584a7a572246de",
"target": {
"file": "drivers/media/test-drivers/vimc/vimc-streamer.c"
}
},
{
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 353.0,
"function_hash": "150396924922414040961000058668502494337"
},
"id": "CVE-2025-22028-d79709af",
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a505075730d23ccc19fc4ac382a0ed73b630c057",
"target": {
"file": "drivers/media/test-drivers/vimc/vimc-streamer.c",
"function": "vimc_streamer_pipeline_terminate"
}
},
{
"deprecated": false,
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"187964675120121735367084158501621918160",
"72020918560712982789959621135173119824",
"5735071825308482674844104372635310174",
"125922966049075630553949817963395470074"
]
},
"id": "CVE-2025-22028-e235ad41",
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7a58d4c4cf8ff60ab1f93399deefaf6057da91c7",
"target": {
"file": "drivers/media/test-drivers/vimc/vimc-streamer.c"
}
}
]