cbcvebase.
CVE-2025-71122
published 2026-01-14

CVE-2025-71122: In the Linux kernel, the following vulnerability has been resolved: iommufd/selftest: Check for overflow in IOMMU_TEST_OP_ADD_RESERVED syzkaller found it could…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.18%
7.9th percentile
In the Linux kernel, the following vulnerability has been resolved: iommufd/selftest: Check for overflow in IOMMU_TEST_OP_ADD_RESERVED syzkaller found it could overflow math in the test infrastructure and cause a WARN_ON by corrupting the reserved interval tree. This only effects test kernels with CONFIG_IOMMUFD_TEST. Validate the user input length in the test ioctl.

Affected

45 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.18.3-1 (forky)linux 6.18.3-1 (forky)
linuxlinux
linuxlinux>= f4b20bb34c83dceade5470288f48f94ce3598ada < 4cc829d61f10c20523fd4085c1546e741a792a974cc829d61f10c20523fd4085c1546e741a792a97
linuxlinux>= f4b20bb34c83dceade5470288f48f94ce3598ada < e6c122cffcbb2e84d321ec8ba0e38ce8e7c10925e6c122cffcbb2e84d321ec8ba0e38ce8e7c10925
linuxlinux>= f4b20bb34c83dceade5470288f48f94ce3598ada < b166b8e0a381429fefd9180e67fbc834b3cee82fb166b8e0a381429fefd9180e67fbc834b3cee82f
linuxlinux>= f4b20bb34c83dceade5470288f48f94ce3598ada < e6a973af11135439de32ece3b9cbe3bfc043bea8e6a973af11135439de32ece3b9cbe3bfc043bea8
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.3-16.18.3-1
linuxlinux_kernel>= 6.13 < 6.18.36.18.3
linuxlinux_kernel>= 6.13.0 < 6.18.36.18.3
linuxlinux_kernel>= 6.2.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.2.1 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7 < 6.12.646.12.64
linuxlinux_kernel>= 6.7.0 < 6.12.646.12.64
ubuntulinux-aws
ubuntulinux-aws-6.17
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-6.17
ubuntulinux-azure-6.8
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
vendor_ubuntu6.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.