-

CVE-2025-71075

In the Linux kernel, the following vulnerability has been resolved:

scsi: aic94xx: fix use-after-free in device removal path

The asd_pci_remove() function fails to synchronize with pending tasklets
before freeing the asd_ha structure, leading to a potential
use-after-free vulnerability.

When a device removal is triggered (via hot-unplug or module unload),
race condition can occur.

The fix adds tasklet_kill() before freeing the asd_ha structure,
ensuring all scheduled tasklets complete before cleanup proceeds.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version < c8f6f88cd1df35155258285c4f43268b361819df
Version 2908d778ab3e244900c310974e1fc1c69066e450
Status affected
Version < 278455a82245a572aeb218a6212a416a98e418de
Version 2908d778ab3e244900c310974e1fc1c69066e450
Status affected
Version < b3e655e52b98a1d3df41c8e42035711e083099f8
Version 2908d778ab3e244900c310974e1fc1c69066e450
Status affected
Version < e354793a7ab9bb0934ea699a9d57bcd1b48fc27b
Version 2908d778ab3e244900c310974e1fc1c69066e450
Status affected
Version < a41dc180b6e1229ae49ca290ae14d82101c148c3
Version 2908d778ab3e244900c310974e1fc1c69066e450
Status affected
Version < 751c19635c2bfaaf2836a533caa3663633066dcf
Version 2908d778ab3e244900c310974e1fc1c69066e450
Status affected
Version < f6ab594672d4cba08540919a4e6be2e202b60007
Version 2908d778ab3e244900c310974e1fc1c69066e450
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 2.6.19
Status affected
Version < 2.6.19
Version 0
Status unaffected
Version <= 5.10.*
Version 5.10.248
Status unaffected
Version <= 5.15.*
Version 5.15.198
Status unaffected
Version <= 6.1.*
Version 6.1.160
Status unaffected
Version <= 6.6.*
Version 6.6.120
Status unaffected
Version <= 6.12.*
Version 6.12.64
Status unaffected
Version <= 6.18.*
Version 6.18.3
Status unaffected
Version <= *
Version 6.19-rc1
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.088
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.