HomeDefectsLIN1025-1423
Fixed

LIN1025-1423 : Security Advisory - linux - CVE-2025-37971

Created: May 20, 2025    Updated: Sep 1, 2025
Resolved Date: May 21, 2025
Found In Version: 10.25.33.1
Severity: Standard
Applicable for: Wind River Linux LTS 25
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

staging: bcm2835-camera: Initialise dev in v4l2_dev

Commit 42a2f6664e18 ("staging: vc04_services: Move global g_state to
vchiq_state") changed mmal_init to pass dev->v4l2_dev.dev to
vchiq_mmal_init, however nothing iniitialised dev->v4l2_dev, so we got
a NULL pointer dereference.

Set dev->v4l2_dev.dev during bcm2835_mmal_probe. The device pointer
could be passed into v4l2_device_register to set it, however that also
has other effects that would need additional changes.

CREATE(Triage):(User=admin) CVE-2025-37971 (https://nvd.nist.gov/vuln/detail/CVE-2025-37971)