cbcvebase.
CVE-2025-71131
published 2026-01-14

CVE-2025-71131: In the Linux kernel, the following vulnerability has been resolved: crypto: seqiv - Do not use req->iv after crypto_aead_encrypt As soon as crypto_aead_encrypt…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.0th percentile
In the Linux kernel, the following vulnerability has been resolved: crypto: seqiv - Do not use req->iv after crypto_aead_encrypt As soon as crypto_aead_encrypt is called, the underlying request may be freed by an asynchronous completion. Thus dereferencing req->iv after it returns is invalid. Instead of checking req->iv against info, create a new variable unaligned_info and use it for that purpose instead.

Affected

66 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 0a270321dbf948963aeb0e8382fe17d2c2eb3771 < 18202537856e0fae079fed2c9308780bcff2bb9d18202537856e0fae079fed2c9308780bcff2bb9d
linuxlinux>= 0a270321dbf948963aeb0e8382fe17d2c2eb3771 < baf0e2d1e03ddb04781dfe7f22a654d3611f69b2baf0e2d1e03ddb04781dfe7f22a654d3611f69b2
linuxlinux>= 0a270321dbf948963aeb0e8382fe17d2c2eb3771 < 50f196d2bbaee4ab2494bb1b0d294deba292951a50f196d2bbaee4ab2494bb1b0d294deba292951a
linuxlinux>= 0a270321dbf948963aeb0e8382fe17d2c2eb3771 < 0279978adec6f1296af66b642cce641c6580be460279978adec6f1296af66b642cce641c6580be46
linuxlinux>= 0a270321dbf948963aeb0e8382fe17d2c2eb3771 < ccbb96434d88e32358894c879457b33f7508e798ccbb96434d88e32358894c879457b33f7508e798
linuxlinux>= 0a270321dbf948963aeb0e8382fe17d2c2eb3771 < 5476f7f8a311236604b78fcc5b2a63b3a61b01695476f7f8a311236604b78fcc5b2a63b3a61b0169
linuxlinux>= 0a270321dbf948963aeb0e8382fe17d2c2eb3771 < 50fdb78b7c0bcc550910ef69c0984e751cac72fa50fdb78b7c0bcc550910ef69c0984e751cac72fa
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.5-16.18.5-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 2.6.25 < 5.10.2485.10.248

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.