In the Linux kernel, the following vulnerability has been resolved:
media: venus: hfi: avoid null dereference in deinit
If venus_probe fails at pm_runtime_put_sync the error handling first calls hfi_destroy and afterwards hfi_core_deinit. As hfi_destroy sets core->ops to NULL, hfi_core_deinit cannot call the core_deinit function anymore.
Avoid this null pointer derefence by skipping the call when necessary.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Feb 27, 2025 | Feb 27, 2025 |
| Ubuntu | — | Upgrade linux-realtimeUpgrade linux-aws-5.4Upgrade linux-oracle-5.15Upgrade linux-awsUpgrade linux-azureUpgrade linux-aws-hweUpgrade linux-gkeUpgrade linux-raspiUpgrade linux-riscv-5.15Upgrade linux-oracle-5.4Upgrade linux-lowlatency-hwe-5.15Upgrade linux-ibm-5.4Upgrade linux-raspi-5.4Upgrade linux-aws-5.15Upgrade linux-fipsUpgrade linux-bluefieldUpgrade linux-intel-iotgUpgrade linux-hwe-5.15Upgrade linuxUpgrade linux-lowlatencyUpgrade linux-gcp-4.15Upgrade linux-gcp-5.15Upgrade linux-gcp-fipsUpgrade linux-azure-5.15Upgrade linux-gkeopUpgrade linux-azure-5.4Upgrade linux-gcp-5.4Upgrade linux-ibmUpgrade linux-azure-fde-5.15Upgrade linux-nvidiaUpgrade linux-azure-4.15Upgrade linux-aws-fipsUpgrade linux-kvmUpgrade linux-oracleUpgrade linux-intel-iotg-5.15Upgrade linux-iotUpgrade linux-azure-fipsUpgrade linux-hwe-5.4Upgrade linux-hweUpgrade linux-gcp | Mar 3, 2025 | Feb 26, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Feb 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub