-

CVE-2025-71071

In the Linux kernel, the following vulnerability has been resolved:

iommu/mediatek: fix use-after-free on probe deferral

The driver is dropping the references taken to the larb devices during
probe after successful lookup as well as on errors. This can
potentially lead to a use-after-free in case a larb device has not yet
been bound to its driver so that the iommu driver probe defers.

Fix this by keeping the references as expected while the iommu driver is
bound.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version < 896ec55da3b90bdb9fc04fedc17ad8c359b2eee5
Version 8412e5dd24ffc8bc21a00bfaa0b80d4596cdc9da
Status affected
Version < 5c04217d06a1161aaf36267e9d971ab6f847d5a7
Version 26593928564cf5b576ff05d3cbd958f57c9534bb
Status affected
Version < 1ef70a0b104ae8011811f60bcfaa55ff49385171
Version 26593928564cf5b576ff05d3cbd958f57c9534bb
Status affected
Version < f6c08d3aa441bbc1956e9d65f1cbb89113a5aa8a
Version 26593928564cf5b576ff05d3cbd958f57c9534bb
Status affected
Version < de83d4617f9fe059623e97acf7e1e10d209625b5
Version 26593928564cf5b576ff05d3cbd958f57c9534bb
Status affected
Version 51080de72e26771f0ed9d44982974279ccbc92b8
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 6.2
Status affected
Version < 6.2
Version 0
Status unaffected
Version <= 6.1.*
Version 6.1.160
Status unaffected
Version <= 6.6.*
Version 6.6.120
Status unaffected
Version <= 6.12.*
Version 6.12.64
Status unaffected
Version <= 6.18.*
Version 6.18.3
Status unaffected
Version <= *
Version 6.19-rc1
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.056
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.