cbcvebase.
CVE-2025-71071
published 2026-01-13

CVE-2025-71071: In the Linux kernel, the following vulnerability has been resolved: iommu/mediatek: fix use-after-free on probe deferral The driver is dropping the references…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
2.6th percentile
In the Linux kernel, the following vulnerability has been resolved: iommu/mediatek: fix use-after-free on probe deferral The driver is dropping the references taken to the larb devices during probe after successful lookup as well as on errors. This can potentially lead to a use-after-free in case a larb device has not yet been bound to its driver so that the iommu driver probe defers. Fix this by keeping the references as expected while the iommu driver is bound.

Affected

54 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 26593928564cf5b576ff05d3cbd958f57c9534bb < 5c04217d06a1161aaf36267e9d971ab6f847d5a75c04217d06a1161aaf36267e9d971ab6f847d5a7
linuxlinux>= 26593928564cf5b576ff05d3cbd958f57c9534bb < 1ef70a0b104ae8011811f60bcfaa55ff493851711ef70a0b104ae8011811f60bcfaa55ff49385171
linuxlinux>= 26593928564cf5b576ff05d3cbd958f57c9534bb < f6c08d3aa441bbc1956e9d65f1cbb89113a5aa8af6c08d3aa441bbc1956e9d65f1cbb89113a5aa8a
linuxlinux>= 26593928564cf5b576ff05d3cbd958f57c9534bb < de83d4617f9fe059623e97acf7e1e10d209625b5de83d4617f9fe059623e97acf7e1e10d209625b5
linuxlinux>= 6.0.16 < 6.16.1
linuxlinux>= 6.1.2 < 6.1.1606.1.160
linuxlinux>= 8412e5dd24ffc8bc21a00bfaa0b80d4596cdc9da < 896ec55da3b90bdb9fc04fedc17ad8c359b2eee5896ec55da3b90bdb9fc04fedc17ad8c359b2eee5
linuxlinux_kernel< 6.12.646.12.64
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.3-16.18.3-1
linuxlinux_kernel>= 0 < 6.1.1606.1.160
linuxlinux_kernel>= 6.0.16 < 6.16.1
linuxlinux_kernel>= 6.1.2 < 6.1.1606.1.160
linuxlinux_kernel>= 6.13 < 6.18.36.18.3
linuxlinux_kernel>= 6.2.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.2.1 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7 < 6.12.646.12.64
linuxlinux_kernel>= 6.7.0 < 6.18.36.18.3

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu6.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.