PT-2025-16668 · Linux+5 · Linux Kernel+5

Published

2025-03-05

·

Updated

2026-05-26

·

CVE-2025-22028

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.13.0-rc2-syzkaller-00362-g2d8308bf5b67
Description A warning was reported by Syzbot due to a check in call s stream() that verifies whether the .s stream() operation is warranted for unstarted or stopped subdevs. The issue arises from the vimc streamer pipeline terminate() function not properly handling entities that have not been started. To address this, a fix was implemented to ensure that entities skip the call to .s stream() unless they have been previously properly started. The estimated number of potentially affected devices is not available.
Recommendations For Linux kernel versions prior to 6.13.0-rc2-syzkaller-00362-g2d8308bf5b67, consider updating to a newer version to mitigate the risk. As a temporary workaround, consider disabling the vimc streamer pipeline terminate() function until a patch is available. Restrict access to the vulnerable vimc-streamer module to minimize the risk of exploitation. Avoid using the s stream operation in the affected API endpoints until the issue is resolved.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2026-01407
CVE-2025-22028
ECHO-51E0-FEA1-6ED2
OESA-2025-1594
OESA-2025-1595
SUSE-SU-2025:01982-1
SUSE-SU-2025_01982-1
USN-7594-1
USN-7594-2
USN-7594-3
USN-7605-1
USN-7605-2
USN-7606-1
USN-7628-1
USN-7835-1
USN-7835-2
USN-7835-3
USN-7835-4
USN-7835-5
USN-7835-6
USN-7887-1
USN-7887-2
USN-7940-1
USN-7940-2

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu