CVE-2025-23160: Debian Linux

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Fix a resource leak related to the scp device in FW initialization On Mediatek devices with a system companion processor (SCP) the mtk_scp structure has to be removed explicitly to avoid a resource leak. Free the structure in case the allocation of the firmware structure fails during the firmware initialization.

Affected products

  • Debian Debian Linux: version 11.0 only
  • Linux Linux Kernel: from 6.1.130, before 6.1.153 (fixed in 6.1.153); from 6.6.36, before 6.6.88 (fixed in 6.6.88); from 6.9.7, before 6.12.24 (fixed in 6.12.24); from 6.13, before 6.13.12 (fixed in 6.13.12); from 6.14, before 6.14.3 (fixed in 6.14.3)

Published 2025-05-01. Last modified 2026-08-23.