PT-2025-46765 · Linux+3 · Linux Kernel+3

Published

2025-08-22

·

Updated

2026-05-26

·

CVE-2025-40208

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux Kernel (affected versions not specified)
Description The Linux kernel's qcom-iris driver contains an issue where module removal can fail if firmware download fails. Specifically, if the firmware download for the qcom/vpu/vpu33 p4.mbn file fails, the driver may not properly clean up resources, leading to runtime errors and potential system instability. The issue manifests as warnings related to clock disabling and runtime PM usage count underflows during module removal. The fix skips deinitialization if the initialization process was unsuccessful.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-14661
CVE-2025-40208
USN-8029-1
USN-8029-2
USN-8029-3
USN-8030-1
USN-8048-1

Affected Products

Linux Kernel
Linuxmint
Ubuntu
Qcom/Vpu/Vpu33 P4.Mbn