Answer in brief
CVE-2025-23160 records a Medium severity (CVSS 5.5) vulnerability in media: mediatek: vcodec: Fix a resource leak related to the scp device in FW initialization. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC CN 4100 (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC CN 4100 (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=ac79a923365ae1e524398087cf16313cdbd7a144 <beaefe8dbb261f36376bb533a89ed69ab38e6747 || >=19ef02106c990bf4235365a08b9d8d2fee37272a <2540a81d5532829150b2e7cca977313b524066a9 || >=eeb62bb4ca22db17f7dfe8fb8472e0442df3d92f <69dd5bbdd79c65445bb17c3c53510783bc1d756c || >=f066882293b5ad359e44c4ed24ab1811ffb0b354 <fd7bb97ede487b9f075707b7408a9073e0d474b1 || >=53dbe08504442dc7ba4865c09b3bbf5fe849681b <9f009fa823c54ca0857c81f7525ea5a5d32de29c || >=53dbe08504442dc7ba4865c09b3bbf5fe849681b <d6cb086aa52bd51378a4c9e2b25d2def97770205 || >=53dbe08504442dc7ba4865c09b3bbf5fe849681b <ac94e1db4b2053059779472eb58a64d504964240 || >=53dbe08504442dc7ba4865c09b3bbf5fe849681b <4936cd5817af35d23e4d283f48fa59a18ef481e4 || 3a693c7e243b932faee5c1fb728efa73f0abc39b || >=6.1.130 <6.1.153 || >=6.6.36 <6.6.88 || >=6.9.7 <6.10 | beaefe8dbb261f36376bb533a89ed69ab38e6747, 2540a81d5532829150b2e7cca977313b524066a9, 69dd5bbdd79c65445bb17c3c53510783bc1d756c, fd7bb97ede487b9f075707b7408a9073e0d474b1, 9f009fa823c54ca0857c81f7525ea5a5d32de29c, d6cb086aa52bd51378a4c9e2b25d2def97770205, ac94e1db4b2053059779472eb58a64d504964240, 4936cd5817af35d23e4d283f48fa59a18ef481e4, 6.1.153, 6.6.88, 6.10 |
| Linux/Linuxgeneric | 6.10 | Not reported |
| Siemens/SIMATIC CN 4100generic | >=0 <V5.0 | V5.0 |
Published upstream
May 1, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 23, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 23, 2026
In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Fix a resource leak related to the scp device in FW initialization On Mediatek devices with a system companion processor (SCP) the mtk_scp structure has to be removed explicitly to avoid a resource leak. Free the structure in case the allocation of the firmware structure fails during the firmware initialization.
Quoted source text, attributed separately from HOL analysis.