cbcvebase.
CVE-2025-71081
published 2026-01-13

CVE-2025-71081: In the Linux kernel, the following vulnerability has been resolved: ASoC: stm32: sai: fix OF node leak on probe The reference taken to the sync provider OF…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.11%
1.5th percentile
In the Linux kernel, the following vulnerability has been resolved: ASoC: stm32: sai: fix OF node leak on probe The reference taken to the sync provider OF node when probing the platform device is currently only dropped if the set_sync() callback fails during DAI probe. Make sure to drop the reference on platform probe failures (e.g. probe deferral) and on driver unbind. This also avoids a potential use-after-free in case the DAI is ever reprobed without first rebinding the platform driver.

Affected

55 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 5914d285f6b782892a91d6621723fdc41a775b15 < 7daa50a2157e41c964b745ab1dc378b5b3b626d17daa50a2157e41c964b745ab1dc378b5b3b626d1
linuxlinux>= 5914d285f6b782892a91d6621723fdc41a775b15 < acda653169e180b1d860dbb6bc5aceb105858394acda653169e180b1d860dbb6bc5aceb105858394
linuxlinux>= 5914d285f6b782892a91d6621723fdc41a775b15 < 4054a3597d047f3fe87864ef87f399b5d523e6c04054a3597d047f3fe87864ef87f399b5d523e6c0
linuxlinux>= 5914d285f6b782892a91d6621723fdc41a775b15 < bae74771fc5d3b2a9cf6f5aa64596083d032c4a3bae74771fc5d3b2a9cf6f5aa64596083d032c4a3
linuxlinux>= 5914d285f6b782892a91d6621723fdc41a775b15 < 3752afcc6d80d5525e236e329895ba2cb93bcb263752afcc6d80d5525e236e329895ba2cb93bcb26
linuxlinux>= 5914d285f6b782892a91d6621723fdc41a775b15 < 23261f0de09427367e99f39f588e31e2856a690e23261f0de09427367e99f39f588e31e2856a690e
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.5-16.18.5-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 4.15.0 < 5.15.1985.15.198
linuxlinux_kernel>= 4.15.1 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16 < 6.1.1606.1.160
linuxlinux_kernel>= 5.16.0 < 6.1.1606.1.160
linuxlinux_kernel>= 6.13 < 6.18.46.18.4
linuxlinux_kernel>= 6.13.0 < 6.18.46.18.4
linuxlinux_kernel>= 6.2 < 6.6.1206.6.120
linuxlinux_kernel>= 6.2.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7 < 6.12.646.12.64
linuxlinux_kernel>= 6.7.0 < 6.12.646.12.64

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.