cbcvebase.
CVE-2025-71129
published 2026-01-14

CVE-2025-71129: In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Sign extend kfunc call arguments The kfunc calls are native calls so they…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.11%
1.7th percentile
In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Sign extend kfunc call arguments The kfunc calls are native calls so they should follow LoongArch calling conventions. Sign extend its arguments properly to avoid kernel panic. This is done by adding a new emit_abi_ext() helper. The emit_abi_ext() helper performs extension in place meaning a value already store in the target register (Note: this is different from the existing sign_extend() helper and thus we can't reuse it).

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.18.5-1 (forky)linux 6.18.5-1 (forky)
linuxlinux
linuxlinux>= 5dc615520c4dfb358245680f1904bad61116648e < fd43edf357a3a1f5ed1c4bf450b60001c9091c39fd43edf357a3a1f5ed1c4bf450b60001c9091c39
linuxlinux>= 5dc615520c4dfb358245680f1904bad61116648e < 0d666db731e95890e0eda7ea61bc925fd2be90c60d666db731e95890e0eda7ea61bc925fd2be90c6
linuxlinux>= 5dc615520c4dfb358245680f1904bad61116648e < 321993a874f571a94b5a596f1132f798c663b56e321993a874f571a94b5a596f1132f798c663b56e
linuxlinux>= 5dc615520c4dfb358245680f1904bad61116648e < 3f5a238f24d7b75f9efe324d3539ad388f58536e3f5a238f24d7b75f9efe324d3539ad388f58536e
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.5-16.18.5-1
linuxlinux_kernel>= 6.1.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.1.1 < 6.6.1206.6.120
linuxlinux_kernel>= 6.13 < 6.18.46.18.4
linuxlinux_kernel>= 6.13.0 < 6.18.46.18.4
linuxlinux_kernel>= 6.7 < 6.12.646.12.64
linuxlinux_kernel>= 6.7.0 < 6.12.646.12.64

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.