We opened a Support Request to AWS and seems that if you make changes to ECR repository policy or IAM Policy, you must redeploy the lambda.
In our case seems that CloudFormation made a DeleteRepositoryPolicy action that causes the loss of permission.
Even if you restore the permission, seems have no effects.
Hope this helps, thanks