CVE-2025-38044
Estado: AnalizadaMedia (5.5)—
In the Linux kernel, the following vulnerability has been resolved:
media: cx231xx: set device_caps for 417
The video_device for the MPEG encoder did not set device_caps.
Add this, otherwise the video device can't be registered (you get a WARN_ON instead).
Not seen before since currently 417 support is disabled, but I found this while experimenting with it.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- NVD-CWE-noinfo
Referencias
- https://git.kernel.org/stable/c/0884dd3abbe80307a2d4cbdbe5e312be164f8adb
- https://git.kernel.org/stable/c/2ad41beb7df3bd63b209842d16765ec59dafe6e4
- https://git.kernel.org/stable/c/4731d5328f507ae8fd8a57abbca9119ec7a8d665
- https://git.kernel.org/stable/c/5c9eca180a4235abd56cc7f7308ca72128d93dce
- https://git.kernel.org/stable/c/9d1a5be86dbe074bd8dd6bdd63a99d6bb66d5930
- https://git.kernel.org/stable/c/a79efc44b51432490538a55b9753a721f7d3ea42
- https://git.kernel.org/stable/c/c91447e35b9bea60bda4408c48e7891d14351021
- https://git.kernel.org/stable/c/e43fd82bb2110bf9d13d800cdc49cceddfd0ede5
- https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-38044",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "8c3854d03bd7b86e8f36e6d9b07b4a6bc20deccd",
"lessThan": "2ad41beb7df3bd63b209842d16765ec59dafe6e4",
"versionType": "git"
},
{
"status": "affected",
"version": "8c3854d03bd7b86e8f36e6d9b07b4a6bc20deccd",
"lessThan": "0884dd3abbe80307a2d4cbdbe5e312be164f8adb",
"versionType": "git"
},
{
"status": "affected",
"version": "8c3854d03bd7b86e8f36e6d9b07b4a6bc20deccd",
"lessThan": "c91447e35b9bea60bda4408c48e7891d14351021",
"versionType": "git"
},
{
"status": "affected",
"version": "8c3854d03bd7b86e8f36e6d9b07b4a6bc20deccd",
"lessThan": "9d1a5be86dbe074bd8dd6bdd63a99d6bb66d5930",
"versionType": "git"
},
{
"status": "affected",
"version": "8c3854d03bd7b86e8f36e6d9b07b4a6bc20deccd",
"lessThan": "5c9eca180a4235abd56cc7f7308ca72128d93dce",
"versionType": "git"
},
{
"status": "affected",
"version": "8c3854d03bd7b86e8f36e6d9b07b4a6bc20deccd",
"lessThan": "4731d5328f507ae8fd8a57abbca9119ec7a8d665",
"versionType": "git"
},
{
"status": "affected",
"version": "8c3854d03bd7b86e8f36e6d9b07b4a6bc20deccd",
"lessThan": "e43fd82bb2110bf9d13d800cdc49cceddfd0ede5",
"versionType": "git"
},
{
"status": "affected",
"version": "8c3854d03bd7b86e8f36e6d9b07b4a6bc20deccd",
"lessThan": "a79efc44b51432490538a55b9753a721f7d3ea42",
"versionType": "git"
}
],
"programFiles": [
"drivers/media/usb/cx231xx/cx231xx-417.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.3",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.4.294",
"versionType": "semver",
"lessThanOrEqual": "5.4.*"
},
{
"status": "unaffected",
"version": "5.10.238",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.185",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.141",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.93",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.31",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.14.9",
"versionType": "semver",
"lessThanOrEqual": "6.14.*"
},
{
"status": "unaffected",
"version": "6.15",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/media/usb/cx231xx/cx231xx-417.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2025-06-18T10:15:36.913",
"references": [
{
"url": "https://git.kernel.org/stable/c/0884dd3abbe80307a2d4cbdbe5e312be164f8adb",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2ad41beb7df3bd63b209842d16765ec59dafe6e4",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/4731d5328f507ae8fd8a57abbca9119ec7a8d665",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5c9eca180a4235abd56cc7f7308ca72128d93dce",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9d1a5be86dbe074bd8dd6bdd63a99d6bb66d5930",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a79efc44b51432490538a55b9753a721f7d3ea42",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c91447e35b9bea60bda4408c48e7891d14351021",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e43fd82bb2110bf9d13d800cdc49cceddfd0ede5",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: cx231xx: set device_caps for 417\n\nThe video_device for the MPEG encoder did not set device_caps.\n\nAdd this, otherwise the video device can't be registered (you get a\nWARN_ON instead).\n\nNot seen before since currently 417 support is disabled, but I found\nthis while experimenting with it."
},
{
"lang": "es",
"value": "En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: media: cx231xx: se estableció device_caps para 417. El dispositivo de video del codificador MPEG no estableció device_caps. Añada esto; de lo contrario, el dispositivo de video no se podrá registrar (en su lugar, se obtendrá un WARN_ON). No se había observado antes, ya que la compatibilidad con 417 está deshabilitada, pero lo encontré al experimentar con él."
}
],
"lastModified": "2026-06-17T09:15:56.580",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "093AFCC1-07FE-4A32-A1F0-9B1F9197071E",
"versionEndExcluding": "5.4.294"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0DAAEF7F-D560-47FC-8B65-20404DB82432",
"versionEndExcluding": "5.10.238",
"versionStartIncluding": "5.5"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E11820B2-24BD-40A8-9E6B-5BC447252321",
"versionEndExcluding": "5.15.185",
"versionStartIncluding": "5.11"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7CEA8241-A858-4009-B4EE-31C62772811A",
"versionEndExcluding": "6.1.141",
"versionStartIncluding": "5.16"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "50A4A9DE-24AB-4FB4-AACD-85D8EABB0571",
"versionEndExcluding": "6.6.93",
"versionStartIncluding": "6.2"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1AE98841-5774-4B45-A81C-2D188DB7E5C3",
"versionEndExcluding": "6.12.31",
"versionStartIncluding": "6.7"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A9B72DD1-715C-4101-A720-1C8D70044C06",
"versionEndExcluding": "6.14.9",
"versionStartIncluding": "6.13"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FA6FEEC2-9F11-4643-8827-749718254FED"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}