CVE-2025-71129
published 2026-01-14CVE-2025-71129: In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Sign extend kfunc call arguments The kfunc calls are native calls so they…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.11%
1.7th percentile
In the Linux kernel, the following vulnerability has been resolved:
LoongArch: BPF: Sign extend kfunc call arguments
The kfunc calls are native calls so they should follow LoongArch calling
conventions. Sign extend its arguments properly to avoid kernel panic.
This is done by adding a new emit_abi_ext() helper. The emit_abi_ext()
helper performs extension in place meaning a value already store in the
target register (Note: this is different from the existing sign_extend()
helper and thus we can't reuse it).
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.18.5-1 (forky) | linux 6.18.5-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= 5dc615520c4dfb358245680f1904bad61116648e < fd43edf357a3a1f5ed1c4bf450b60001c9091c39 | fd43edf357a3a1f5ed1c4bf450b60001c9091c39 |
| linux | linux | >= 5dc615520c4dfb358245680f1904bad61116648e < 0d666db731e95890e0eda7ea61bc925fd2be90c6 | 0d666db731e95890e0eda7ea61bc925fd2be90c6 |
| linux | linux | >= 5dc615520c4dfb358245680f1904bad61116648e < 321993a874f571a94b5a596f1132f798c663b56e | 321993a874f571a94b5a596f1132f798c663b56e |
| linux | linux | >= 5dc615520c4dfb358245680f1904bad61116648e < 3f5a238f24d7b75f9efe324d3539ad388f58536e | 3f5a238f24d7b75f9efe324d3539ad388f58536e |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.12.69-1 | 6.12.69-1 |
| linux | linux_kernel | >= 0 < 6.18.5-1 | 6.18.5-1 |
| linux | linux_kernel | >= 6.1.0 < 6.6.120 | 6.6.120 |
| linux | linux_kernel | >= 6.1.1 < 6.6.120 | 6.6.120 |
| linux | linux_kernel | >= 6.13 < 6.18.4 | 6.18.4 |
| linux | linux_kernel | >= 6.13.0 < 6.18.4 | 6.18.4 |
| linux | linux_kernel | >= 6.7 < 6.12.64 | 6.12.64 |
| linux | linux_kernel | >= 6.7.0 < 6.12.64 | 6.12.64 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: LoongArch: BPF: Sign extend kfunc call arguments
vendor_redhat·2026-01-14·CVSS 5.5
CVE-2025-71129 [MEDIUM] kernel: LoongArch: BPF: Sign extend kfunc call arguments
kernel: LoongArch: BPF: Sign extend kfunc call arguments
In the Linux kernel, the following vulnerability has been resolved:
LoongArch: BPF: Sign extend kfunc call arguments
The kfunc calls are native calls so they should follow LoongArch calling
conventions. Sign extend its arguments properly to avoid kernel panic.
This is done by adding a new emit_abi_ext() helper. The emit_abi_ext()
helper performs extension in place meaning a value already store in the
target register (Note: this is different from the existing sign_extend()
helper and thus we can't reuse it).
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux
Debian
CVE-2025-71129: linux - In the Linux kernel, the following vulnerability has been resolved: LoongArch: ...
vendor_debian·2025·CVSS 5.5
CVE-2025-71129 [MEDIUM] CVE-2025-71129: linux - In the Linux kernel, the following vulnerability has been resolved: LoongArch: ...
In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Sign extend kfunc call arguments The kfunc calls are native calls so they should follow LoongArch calling conventions. Sign extend its arguments properly to avoid kernel panic. This is done by adding a new emit_abi_ext() helper. The emit_abi_ext() helper performs extension in place meaning a value already store in the target register (Note: this is different from the existing sign_extend() helper and thus we can't reuse it).
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 6.18.5-1)
sid: resolved (fixed in 6.18.5-1)
trixie: resolved (fixed in 6.12.69-1)
GHSA
GHSA-6c2w-77g9-cccc: In the Linux kernel, the following vulnerability has been resolved:
LoongArch: BPF: Sign extend kfunc call arguments
The kfunc calls are native call
ghsa_unreviewed·2026-01-14
CVE-2025-71129 [MEDIUM] GHSA-6c2w-77g9-cccc: In the Linux kernel, the following vulnerability has been resolved:
LoongArch: BPF: Sign extend kfunc call arguments
The kfunc calls are native call
In the Linux kernel, the following vulnerability has been resolved:
LoongArch: BPF: Sign extend kfunc call arguments
The kfunc calls are native calls so they should follow LoongArch calling
conventions. Sign extend its arguments properly to avoid kernel panic.
This is done by adding a new emit_abi_ext() helper. The emit_abi_ext()
helper performs extension in place meaning a value already store in the
target register (Note: this is different from the existing sign_extend()
helper and thus we can't reuse it).
OSV
LoongArch: BPF: Sign extend kfunc call arguments
osv·2026-01-14·CVSS 5.5
CVE-2025-71129 [MEDIUM] LoongArch: BPF: Sign extend kfunc call arguments
LoongArch: BPF: Sign extend kfunc call arguments
In the Linux kernel, the following vulnerability has been resolved:
LoongArch: BPF: Sign extend kfunc call arguments
The kfunc calls are native calls so they should follow LoongArch calling
conventions. Sign extend its arguments properly to avoid kernel panic.
This is done by adding a new emit_abi_ext() helper. The emit_abi_ext()
helper performs extension in place meaning a value already store in the
target register (Note: this is different from the existing sign_extend()
helper and thus we can't reuse it).
OSV
CVE-2025-71129: In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Sign extend kfunc call arguments The kfunc calls are native calls
osv·2026-01-14·CVSS 5.5
CVE-2025-71129 [MEDIUM] CVE-2025-71129: In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Sign extend kfunc call arguments The kfunc calls are native calls
In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Sign extend kfunc call arguments The kfunc calls are native calls so they should follow LoongArch calling conventions. Sign extend its arguments properly to avoid kernel panic. This is done by adding a new emit_abi_ext() helper. The emit_abi_ext() helper performs extension in place meaning a value already store in the target register (Note: this is different from the existing sign_extend() helper and thus we can't reuse it).
No detection rules found.
No public exploits indexed.
2026-01-14
Published