CVE-2025-71089Missing Synchronization in Linux

Severity
7.8HIGHNVD
EPSS
0.0%
top 98.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13
Latest updateApr 17

Description

In the Linux kernel, the following vulnerability has been resolved: iommu: disable SVA when CONFIG_X86 is set Patch series "Fix stale IOTLB entries for kernel address space", v7. This proposes a fix for a security vulnerability related to IOMMU Shared Virtual Addressing (SVA). In an SVA context, an IOMMU can cache kernel page table entries. When a kernel page table page is freed and reallocated for another purpose, the IOMMU might still hold stale, incorrect entries. This can be exploited to

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages15 packages

NVDlinux/linux_kernel5.25.15.200+4
Debianlinux/linux_kernel< 6.1.164-1+2
CVEListV5linux/linux26b25a2b98e45aeb40eedcedc586ad5034cbd984b34289505180a83607fcfdce14b5a290d0528476+6
debiandebian/linux< linux 6.1.164-1 (bookworm)
debiandebian/linux-6.1< linux 6.1.164-1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-r6cc-j9rp-4f85: In the Linux kernel, the following vulnerability has been resolved: iommu: disable SVA when CONFIG_X86 is set Patch series "Fix stale IOTLB entries2026-01-13
OSV
CVE-2025-71089: In the Linux kernel, the following vulnerability has been resolved: iommu: disable SVA when CONFIG_X86 is set Patch series "Fix stale IOTLB entries fo2026-01-13

📋Vendor Advisories

9
Ubuntu
Linux kernel (GCP) vulnerabilities2026-04-17
Ubuntu
Linux kernel (FIPS) vulnerabilities2026-04-17
Ubuntu
Linux kernel (Real-time) vulnerabilities2026-04-17
Ubuntu
Linux kernel (Real-time) vulnerabilities2026-04-17
Ubuntu
Linux kernel (NVIDIA) vulnerabilities2026-04-17

🕵️Threat Intelligence

1
Wiz
CVE-2025-71089 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2025-71089 — Missing Synchronization in Linux | cvebase