CVE-2025-40208 addresses a bug in the Linux kernel's qcom-iris media driver. Specifically, it resolves an issue where attempting to remove the module after a firmware download failure could lead to kernel warnings and potential system instability due to incorrect clock handling. This vulnerability affects Linux systems utilizing the qcom-iris driver. The vulnerability's severity is considered low. It requires local access to trigger the module unbinding process after a specific firmware download failure, making the attack vector local and the complexity high. The primary impact is system instability or crashes, not direct data compromise or privilege escalation. There is no indication of active exploitation for CVE-2025-40208. No exploit code is publicly available, and there is no community discussion or media coverage surrounding this vulnerability, suggesting it is not a focus for attackers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 6.15CNA affecteddefault affected | |
| Linux | Linux | >= d7378f84e94e14998b3469dcc0d8ce609d049ccc, < 7a0a77b936ff28f59c271172e81cefebf7b2b7a6, >= d7378f84e94e14998b3469dcc0d8ce609d049ccc, < fde38008fc4f43db8c17869491870df24b501543CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.