We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-37971

staging: bcm2835-camera: Initialise dev in v4l2_dev



Description

In the Linux kernel, the following vulnerability has been resolved: staging: bcm2835-camera: Initialise dev in v4l2_dev Commit 42a2f6664e18 ("staging: vc04_services: Move global g_state to vchiq_state") changed mmal_init to pass dev->v4l2_dev.dev to vchiq_mmal_init, however nothing iniitialised dev->v4l2_dev, so we got a NULL pointer dereference. Set dev->v4l2_dev.dev during bcm2835_mmal_probe. The device pointer could be passed into v4l2_device_register to set it, however that also has other effects that would need additional changes.

Reserved 2025-04-16 | Published 2025-05-20 | Updated 2025-05-26 | Assigner Linux

Product status

Default status
unaffected

42a2f6664e18874302623f31edef545ef41e1d14 before 06753f49336ab161ea0e249a0720125b81b7b31b
affected

42a2f6664e18874302623f31edef545ef41e1d14 before b70bdd4923e8b8edbacde2af83ca337bb7005261
affected

42a2f6664e18874302623f31edef545ef41e1d14 before 98698ca0e58734bc5c1c24e5bbc7429f981cd186
affected

Default status
affected

6.10
affected

Any version before 6.10
unaffected

6.12.29
unaffected

6.14.7
unaffected

6.15
unaffected

References

git.kernel.org/...c/06753f49336ab161ea0e249a0720125b81b7b31b

git.kernel.org/...c/b70bdd4923e8b8edbacde2af83ca337bb7005261

git.kernel.org/...c/98698ca0e58734bc5c1c24e5bbc7429f981cd186

cve.org (CVE-2025-37971)

nvd.nist.gov (CVE-2025-37971)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-37971

Support options

Helpdesk Chat, Email, Knowledgebase