PT-2025-46765 · Linux+3 · Linux Kernel+3
Published
2025-08-22
·
Updated
2026-05-26
·
CVE-2025-40208
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux Kernel (affected versions not specified)
Description
The Linux kernel's qcom-iris driver contains an issue where module removal can fail if firmware download fails. Specifically, if the firmware download for the
qcom/vpu/vpu33 p4.mbn file fails, the driver may not properly clean up resources, leading to runtime errors and potential system instability. The issue manifests as warnings related to clock disabling and runtime PM usage count underflows during module removal. The fix skips deinitialization if the initialization process was unsuccessful.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel
Linuxmint
Ubuntu
Qcom/Vpu/Vpu33 P4.Mbn