cbcvebase.
CVE-2025-71147
published 2026-01-23

CVE-2025-71147: In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Fix a memory leak in tpm2_load_cmd 'tpm2_load_cmd' allocates a tempoary blob…

PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.11%
1.7th percentile
In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Fix a memory leak in tpm2_load_cmd 'tpm2_load_cmd' allocates a tempoary blob indirectly via 'tpm2_key_decode' but it is not freed in the failure paths. Address this by wrapping the blob into with a cleanup helper.

Affected

48 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= f2219745250f388edacabe6cca73654131c67d0a < 3fd7df4636d8fd5e3592371967a59412043689363fd7df4636d8fd5e3592371967a5941204368936
linuxlinux>= f2219745250f388edacabe6cca73654131c67d0a < af0689cafb127a8d1af78cc8b72585c9b2a19ecdaf0689cafb127a8d1af78cc8b72585c9b2a19ecd
linuxlinux>= f2219745250f388edacabe6cca73654131c67d0a < 19166de9737218b77122c41a5730ac87025e089f19166de9737218b77122c41a5730ac87025e089f
linuxlinux>= f2219745250f388edacabe6cca73654131c67d0a < 9b015f2918b95bdde2ca9cefa10ef02b138aae1e9b015f2918b95bdde2ca9cefa10ef02b138aae1e
linuxlinux>= f2219745250f388edacabe6cca73654131c67d0a < 9e7c63c69f57b1db1a8a1542359a6167ff8fcef19e7c63c69f57b1db1a8a1542359a6167ff8fcef1
linuxlinux>= f2219745250f388edacabe6cca73654131c67d0a < 62cd5d480b9762ce70d720a81fa5b373052ae05f62cd5d480b9762ce70d720a81fa5b373052ae05f
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.3-16.18.3-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 5.13 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16 < 6.1.1606.1.160
linuxlinux_kernel>= 6.13 < 6.18.36.18.3
linuxlinux_kernel>= 6.2 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7 < 6.12.646.12.64
ubuntulinux-aws
ubuntulinux-aws-6.17
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-5.15
ubuntulinux-azure-6.17
ubuntulinux-azure-6.8

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.