CVE-2025-40197
In the Linux kernel, the following vulnerability has been resolved: media: mc: Clear minor number before put device The device minor should not be cleared after the device is released.
Affected versions
Fixed in
5.4.301,
5.10.246,
5.15.195,
6.1.157,
6.6.113,
6.12.54,
6.17.4,
6.18
and their respective stable series.
References
The following references provide additional information about CVE-2025-40197 including vendor advisories, patch commits, exploit details, and third-party analysis. Links are sourced from the NIST NVD database.
-
PatchKernel patch commithttps://git.kernel.org/stable/c/5d327391f9fafeb0938be4fc538dd0bd54a0b2ef
-
PatchKernel patch commithttps://git.kernel.org/stable/c/64dbc6f50ce92b7da203b1bcdd96a370bbc9b74d
-
PatchKernel patch commithttps://git.kernel.org/stable/c/7bd4e5367d0940ccec4d7546bb6bd019ab2c71aa
Frequently asked questions
-
What is CVE-2025-40197?
CVE-2025-40197 is a unscored severity Linux kernel vulnerability . CVE-2025-40197 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2025-40197?
Yes — CVE-2025-40197 has been patched. Fixed versions include 5.4.301, 5.10.246, 5.15.195 and others.
-
Is CVE-2025-40197 actively exploited?
No — CVE-2025-40197 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.