PT-2025-42784 · Linux+4 · Linux Kernel+4

Published

2025-08-20

·

Updated

2026-05-07

·

CVE-2025-40016

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contained an issue in the uvcvideo driver related to handling of Universal Video Class (UVC) entities. Specifically, the driver did not properly mark invalid entities with the ID UVC INVALID ENTITY ID, as required by the UVC 1.1+ specification. This could lead to warnings and potential issues when processing video streams, particularly in scenarios involving chains of entities referencing themselves or invalid source IDs. The issue was identified through syzkaller testing, which revealed stack traces indicating problems with pad link creation and entity initialization.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Weakness Enumeration

Related Identifiers

AZL-68595
BDU:2025-13569
CVE-2025-40016
ECHO-449E-4443-F29A
MGASA-2025-0309
MGASA-2025-0310
OPENSUSE-SU-2025:15671-1
OPENSUSE-SU-2025:20091-1
OPENSUSE-SU-2026:10301-1
SUSE-SU-2025:21040-1
SUSE-SU-2025:21052-1
SUSE-SU-2025:21056-1
SUSE-SU-2025:21064-1
SUSE-SU-2025:21080-1
SUSE-SU-2025:21147-1
SUSE-SU-2025:21180-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4128-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4140-1
SUSE-SU-2025:4141-1
SUSE-SU-2025:4301-1
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8165-1
USN-8261-1

Affected Products

Debian
Linuxmint
Linux Kernel
Suse
Ubuntu