cbcvebase.
CVE-2025-71075
published 2026-01-13

CVE-2025-71075: In the Linux kernel, the following vulnerability has been resolved: scsi: aic94xx: fix use-after-free in device removal path The asd_pci_remove() function…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
2.6th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: aic94xx: fix use-after-free in device removal path The asd_pci_remove() function fails to synchronize with pending tasklets before freeing the asd_ha structure, leading to a potential use-after-free vulnerability. When a device removal is triggered (via hot-unplug or module unload), race condition can occur. The fix adds tasklet_kill() before freeing the asd_ha structure, ensuring all scheduled tasklets complete before cleanup proceeds.

Affected

66 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 2908d778ab3e244900c310974e1fc1c69066e450 < c8f6f88cd1df35155258285c4f43268b361819dfc8f6f88cd1df35155258285c4f43268b361819df
linuxlinux>= 2908d778ab3e244900c310974e1fc1c69066e450 < 278455a82245a572aeb218a6212a416a98e418de278455a82245a572aeb218a6212a416a98e418de
linuxlinux>= 2908d778ab3e244900c310974e1fc1c69066e450 < b3e655e52b98a1d3df41c8e42035711e083099f8b3e655e52b98a1d3df41c8e42035711e083099f8
linuxlinux>= 2908d778ab3e244900c310974e1fc1c69066e450 < e354793a7ab9bb0934ea699a9d57bcd1b48fc27be354793a7ab9bb0934ea699a9d57bcd1b48fc27b
linuxlinux>= 2908d778ab3e244900c310974e1fc1c69066e450 < a41dc180b6e1229ae49ca290ae14d82101c148c3a41dc180b6e1229ae49ca290ae14d82101c148c3
linuxlinux>= 2908d778ab3e244900c310974e1fc1c69066e450 < 751c19635c2bfaaf2836a533caa3663633066dcf751c19635c2bfaaf2836a533caa3663633066dcf
linuxlinux>= 2908d778ab3e244900c310974e1fc1c69066e450 < f6ab594672d4cba08540919a4e6be2e202b60007f6ab594672d4cba08540919a4e6be2e202b60007
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.3-16.18.3-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 2.6.19 < 5.10.2485.10.248

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.