cbcvebase.
CVE-2025-71099
published 2026-01-13

CVE-2025-71099: In the Linux kernel, the following vulnerability has been resolved: drm/xe/oa: Fix potential UAF in xe_oa_add_config_ioctl() In xe_oa_add_config_ioctl(), we…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.11%
1.8th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/xe/oa: Fix potential UAF in xe_oa_add_config_ioctl() In xe_oa_add_config_ioctl(), we accessed oa_config->id after dropping metrics_lock. Since this lock protects the lifetime of oa_config, an attacker could guess the id and call xe_oa_remove_config_ioctl() with perfect timing, freeing oa_config before we dereference it, leading to a potential use-after-free. Fix this by caching the id in a local variable while holding the lock. v2: (Matt A) - Dropped mutex_unlock(&oa->metrics_lock) ordering change from xe_oa_remove_config_ioctl() (cherry picked from commit 28aeaed130e8e587fd1b73b6d66ca41ccc5a1a31)

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.18.5-1 (forky)linux 6.18.5-1 (forky)
linuxlinux
linuxlinux>= cdf02fe1a94a768cbcd20f5c4e1a1d805f4a06c0 < c6d30b65b7a44dac52ad49513268adbf19eab4a2c6d30b65b7a44dac52ad49513268adbf19eab4a2
linuxlinux>= cdf02fe1a94a768cbcd20f5c4e1a1d805f4a06c0 < 7cdb9a9da935c687563cc682155461fef5f9b48d7cdb9a9da935c687563cc682155461fef5f9b48d
linuxlinux>= cdf02fe1a94a768cbcd20f5c4e1a1d805f4a06c0 < dcb171931954c51a1a7250d558f02b8f36570783dcb171931954c51a1a7250d558f02b8f36570783
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.5-16.18.5-1
linuxlinux_kernel>= 6.11.0 < 6.12.646.12.64
linuxlinux_kernel>= 6.11.1 < 6.12.646.12.64
linuxlinux_kernel>= 6.13 < 6.18.46.18.4
linuxlinux_kernel>= 6.13.0 < 6.18.46.18.4
ubuntulinux-aws
ubuntulinux-aws-6.17
ubuntulinux-azure
ubuntulinux-azure-6.17
ubuntulinux-gcp

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
vendor_ubuntu6.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.