cbcvebase.
CVE-2025-71143
published 2026-01-14

CVE-2025-71143: In the Linux kernel, the following vulnerability has been resolved: clk: samsung: exynos-clkout: Assign .num before accessing .hws Commit f316cdff8d67 ("clk…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.12%
2.4th percentile
In the Linux kernel, the following vulnerability has been resolved: clk: samsung: exynos-clkout: Assign .num before accessing .hws Commit f316cdff8d67 ("clk: Annotate struct clk_hw_onecell_data with __counted_by") annotated the hws member of 'struct clk_hw_onecell_data' with __counted_by, which informs the bounds sanitizer (UBSAN_BOUNDS) about the number of elements in .hws[], so that it can warn when .hws[] is accessed out of bounds. As noted in that change, the __counted_by member must be initialized with the number of elements before the first array access happens, otherwise there will be a warning from each access prior to the initialization because the number of elements is zero. This occurs in exynos_clkout_probe() due to .num being assigned after .hws[] has been accessed: UBSAN: array-index-out-of-bounds in drivers/clk/samsung/clk-exynos-clkout.c:178:18 index 0 is out of range for type 'clk_hw *[*]' Move the .num initialization to before the first access of .hws[], clearing up the warning.

Affected

45 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.18.5-1 (forky)linux 6.18.5-1 (forky)
linuxlinux
linuxlinux>= f316cdff8d677db9ad9c90acb44c4cd535b0ee27 < fbf57f5e453dadadb3d29b2d1dbe067e3dc4e236fbf57f5e453dadadb3d29b2d1dbe067e3dc4e236
linuxlinux>= f316cdff8d677db9ad9c90acb44c4cd535b0ee27 < eb1f3a6ab3efee2b52361879cdc2dc6b11f499c0eb1f3a6ab3efee2b52361879cdc2dc6b11f499c0
linuxlinux>= f316cdff8d677db9ad9c90acb44c4cd535b0ee27 < a317f63255ebc3dac378c79c5bff4f8d0561c290a317f63255ebc3dac378c79c5bff4f8d0561c290
linuxlinux>= f316cdff8d677db9ad9c90acb44c4cd535b0ee27 < cf33f0b7df13685234ccea7be7bfe316b60db4dbcf33f0b7df13685234ccea7be7bfe316b60db4db
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.5-16.18.5-1
linuxlinux_kernel>= 6.13 < 6.18.46.18.4
linuxlinux_kernel>= 6.13.0 < 6.18.46.18.4
linuxlinux_kernel>= 6.6.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.6.1 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7 < 6.12.646.12.64
linuxlinux_kernel>= 6.7.0 < 6.12.646.12.64
ubuntulinux-aws
ubuntulinux-aws-6.17
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-6.17
ubuntulinux-azure-6.8
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
vendor_ubuntu6.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.