DEBIAN-CVE-2025-40208

Source
https://security-tracker.debian.org/tracker/CVE-2025-40208
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-40208.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2025-40208
Upstream
Published
2025-11-12T22:15:48Z
Modified
2025-11-13T11:34:30.455245Z
Summary
[none]
Details

In the Linux kernel, the following vulnerability has been resolved: media: iris: fix module removal if firmware download failed Fix remove if firmware failed to load: qcom-iris aa00000.video-codec: Direct firmware load for qcom/vpu/vpu33p4.mbn failed with error -2 qcom-iris aa00000.video-codec: firmware download failed qcom-iris aa00000.video-codec: core init failed then: $ echo aa00000.video-codec > /sys/bus/platform/drivers/qcom-iris/unbind Triggers: genpd genpd:1:aa00000.video-codec: Runtime PM usage count underflow! ------------[ cut here ]------------ videoccmvs0clk already disabled WARNING: drivers/clk/clk.c:1206 at clkcoredisable+0xa4/0xac, CPU#1: sh/542 <snip> pc : clkcoredisable+0xa4/0xac lr : clkcoredisable+0xa4/0xac <snip> Call trace: clkcoredisable+0xa4/0xac (P) clkdisable+0x30/0x4c irisdisableunprepareclock+0x20/0x48 [qcomiris] irisvpupoweroffhw+0x48/0x58 [qcomiris] irisvpu33poweroffhardware+0x44/0x230 [qcomiris] irisvpupoweroff+0x34/0x84 [qcomiris] iriscoredeinit+0x44/0xc8 [qcomiris] irisremove+0x20/0x48 [qcomiris] platformremove+0x20/0x30 deviceremove+0x4c/0x80 <snip> ---[ end trace 0000000000000000 ]--- ------------[ cut here ]------------ videoccmvs0clk already unprepared WARNING: drivers/clk/clk.c:1065 at clkcoreunprepare+0xf0/0x110, CPU#2: sh/542 <snip> pc : clkcoreunprepare+0xf0/0x110 lr : clkcoreunprepare+0xf0/0x110 <snip> Call trace: clkcoreunprepare+0xf0/0x110 (P) clkunprepare+0x2c/0x44 irisdisableunprepareclock+0x28/0x48 [qcomiris] irisvpupoweroffhw+0x48/0x58 [qcomiris] irisvpu33poweroffhardware+0x44/0x230 [qcomiris] irisvpupoweroff+0x34/0x84 [qcomiris] iriscoredeinit+0x44/0xc8 [qcomiris] irisremove+0x20/0x48 [qcomiris] platformremove+0x20/0x30 deviceremove+0x4c/0x80 <snip> ---[ end trace 0000000000000000 ]--- genpd genpd:0:aa00000.video-codec: Runtime PM usage count underflow! ------------[ cut here ]------------ gccvideoaxi0clk already disabled WARNING: drivers/clk/clk.c:1206 at clkcoredisable+0xa4/0xac, CPU#4: sh/542 <snip> pc : clkcoredisable+0xa4/0xac lr : clkcoredisable+0xa4/0xac <snip> Call trace: clkcoredisable+0xa4/0xac (P) clkdisable+0x30/0x4c irisdisableunprepareclock+0x20/0x48 [qcomiris] irisvpu33poweroffcontroller+0x17c/0x428 [qcomiris] irisvpupoweroff+0x48/0x84 [qcomiris] iriscoredeinit+0x44/0xc8 [qcomiris] irisremove+0x20/0x48 [qcomiris] platformremove+0x20/0x30 deviceremove+0x4c/0x80 <snip> ------------[ cut here ]------------ gccvideoaxi0clk already unprepared WARNING: drivers/clk/clk.c:1065 at clkcoreunprepare+0xf0/0x110, CPU#4: sh/542 <snip> pc : clkcoreunprepare+0xf0/0x110 lr : clkcoreunprepare+0xf0/0x110 <snip> Call trace: clkcoreunprepare+0xf0/0x110 (P) clkunprepare+0x2c/0x44 irisdisableunprepareclock+0x28/0x48 [qcomiris] irisvpu33poweroffcontroller+0x17c/0x428 [qcomiris] irisvpupoweroff+0x48/0x84 [qcomiris] iriscoredeinit+0x44/0xc8 [qcomiris] irisremove+0x20/0x48 [qcomiris] platformremove+0x20/0x30 device_remove+0x4c/0x80 <snip> ---[ end trace 0000000000000000 ]--- Skip deinit if initialization never succeeded.

References

Affected packages

Debian:14 / linux

Package

Name
linux
Purl
pkg:deb/debian/linux?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*

6.12.38-1
6.12.41-1
6.12.43-1~bpo12+1
6.12.43-1
6.12.48-1
6.12.57-1
6.13~rc6-1~exp1
6.13~rc7-1~exp1
6.13.2-1~exp1
6.13.3-1~exp1
6.13.4-1~exp1
6.13.5-1~exp1
6.13.6-1~exp1
6.13.7-1~exp1
6.13.8-1~exp1
6.13.9-1~exp1
6.13.10-1~exp1
6.13.11-1~exp1
6.14.3-1~exp1
6.14.5-1~exp1
6.14.6-1~exp1
6.15~rc7-1~exp1
6.15-1~exp1
6.15.1-1~exp1
6.15.2-1~exp1
6.15.3-1~exp1
6.15.4-1~exp1
6.15.5-1~exp1
6.15.6-1~exp1
6.16~rc7-1~exp1
6.16-1~exp1
6.16.1-1~exp1
6.16.3-1~bpo13+1
6.16.3-1
6.16.5-1
6.16.6-1
6.16.7-1
6.16.8-1
6.16.9-1
6.16.10-1
6.16.11-1
6.16.12-1
6.16.12-2
6.17.2-1~exp1
6.17.5-1~exp1
6.17.6-1
6.17.7-1
6.17.7-2
6.18~rc4-1~exp1
6.18~rc4-1~exp2

Ecosystem specific

{
    "urgency": "not yet assigned"
}