CVE-2025-71119Missing Initialization of Resource in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 93.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 14
Latest updateApr 17

Description

In the Linux kernel, the following vulnerability has been resolved: powerpc/kexec: Enable SMT before waking offline CPUs If SMT is disabled or a partial SMT state is enabled, when a new kernel image is loaded for kexec, on reboot the following warning is observed: kexec: Waking offline cpu 228. WARNING: CPU: 0 PID: 9062 at arch/powerpc/kexec/core_64.c:223 kexec_prepare_cpus+0x1b0/0x1bc [snip] NIP kexec_prepare_cpus+0x1b0/0x1bc LR kexec_prepare_cpus+0x1a0/0x1bc Call Trace: kexec_prepare_cpus+0

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages16 packages

Linuxlinux/linux_kernel6.2.06.6.120+3
NVDlinux/linux_kernel6.1.726.1.160+6
Debianlinux/linux_kernel< 6.1.162-1+2
CVEListV5linux/linux482fa21635c8832db022cd2d649db26b8e6170ac7cccd82a0e4aad192fd74fc60e61ed9aed5857a3+6
debiandebian/linux< linux 6.1.162-1 (bookworm)

Patches

🔴Vulnerability Details

3
GHSA
GHSA-c6m6-8r45-fwg7: In the Linux kernel, the following vulnerability has been resolved: powerpc/kexec: Enable SMT before waking offline CPUs If SMT is disabled or a par2026-01-14
OSV
CVE-2025-71119: In the Linux kernel, the following vulnerability has been resolved: powerpc/kexec: Enable SMT before waking offline CPUs If SMT is disabled or a parti2026-01-14
OSV
powerpc/kexec: Enable SMT before waking offline CPUs2026-01-14

📋Vendor Advisories

9
Ubuntu
Linux kernel (GCP) vulnerabilities2026-04-17
Ubuntu
Linux kernel (FIPS) vulnerabilities2026-04-17
Ubuntu
Linux kernel (Real-time) vulnerabilities2026-04-17
Ubuntu
Linux kernel (Real-time) vulnerabilities2026-04-17
Ubuntu
Linux kernel (NVIDIA) vulnerabilities2026-04-17

🕵️Threat Intelligence

1
Wiz
CVE-2025-71119 Impact, Exploitability, and Mitigation Steps | Wiz