Junglewise Threat Intelligence

CVE-2025-40165: Linux Kernel NXP i.MX8 ISI resource leak in m2m streaming

CVE-2025-40165 · Severity: high · CVSS 7.8 · Published 2025-11-12

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's NXP i.MX8 ISI camera driver could lead to system instability or resource exhaustion. When a video streaming application is interrupted unexpectedly (such as using Ctrl+C), the system may fail to properly release hardware resources. This can prevent the camera hardware from being used by other applications and, in some cases, trigger internal system warnings that could lead to a crash.

Technical details

The vulnerability exists in the 'imx8-isi' media driver's memory-to-memory (m2m) implementation. Imbalanced 'streamon' and 'streamoff' calls, often triggered by abnormal process termination, prevent the 'usage_count' from reaching zero, causing the ISI channel to remain allocated. Additionally, input line widths exceeding 2K can trigger a WARN_ON() in 'mxc_isi_channel_chain'. The fix involves migrating streaming preparation and cleanup logic to the 'vb2' .prepare_streaming() and .unprepare_streaming() operations to ensure proper resource lifecycle management.

Affected products

  • Linux Linux Kernel 6.4 to 6.6.114, 6.12.55, 6.17.5

Timeline

  • 2025-11-12: advisory: CVE published by NVD
  • 2025-08-31: patched: Initial patch committed to stable tree

References

Related threats