UBUNTU-CVE-2025-40015
Dashboard / Vulnerabilities / UBUNTU-CVE-2025-40015
Summary:
Details: In the Linux kernel, the following vulnerability has been resolved: media: stm32-csi: Fix dereference before NULL check In 'stm32_csi_start', 'csidev->s_subdev' is dereferenced directly while assigning a value to the 'src_pad'. However the same value is being checked against NULL at a later point of time indicating that there are chances that the value can be NULL. Move the dereference after the NULL check.
References: https://ubuntu.com/security/CVE-2025-40015, https://www.cve.org/CVERecord?id=CVE-2025-40015, https://git.kernel.org/linus/80eaf32672871bd2623ce6ba13ffc1f018756580, https://git.kernel.org/stable/c/1f053d82e59c785b2b939cbed12f13657f84b296, https://git.kernel.org/stable/c/4eeafff163e80d576c5efc1360ae310c0ceedd02, https://git.kernel.org/stable/c/80eaf32672871bd2623ce6ba13ffc1f018756580
Affected packages
Package
Name: linux-hwe-edge
Purl: pkg:deb/ubuntu/linux-hwe-edge?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
