
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-38237 is a vulnerability discovered in the Linux kernel affecting the media platform component, specifically the exynos4-is driver. The vulnerability was disclosed on July 8, 2025, and involves a synchronization issue in the fimc_is_hw_change_mode() function (NVD, Red Hat).
The vulnerability exists in the fimc_is_hw_change_mode() function where camera modes are changed without waiting for hardware completion. The issue has been assigned a CVSS v3.1 base score of 5.5 with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating a local attack vector with low attack complexity (Red Hat).
The vulnerability can result in corrupted data or system hangs if subsequent operations proceed before the hardware is ready. This occurs because the function changes camera modes without proper synchronization with the hardware state (NVD).
The fix involves adding fimc_is_hw_wait_intmsr0_intmsd0() after mode configuration to ensure hardware state synchronization and stable interrupt handling. This modification has been implemented in the kernel source code (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."