CVE-2025-71156Missing Initialization of Resource in Linux

Severity
7.8HIGHNVD
EPSS
0.0%
top 95.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 23
Latest updateApr 17

Description

In the Linux kernel, the following vulnerability has been resolved: gve: defer interrupt enabling until NAPI registration Currently, interrupts are automatically enabled immediately upon request. This allows interrupt to fire before the associated NAPI context is fully initialized and cause failures like below: [ 0.946369] Call Trace: [ 0.946369] [ 0.946369] __napi_poll+0x2a/0x1e0 [ 0.946369] net_rx_action+0x2f9/0x3f0 [ 0.946369] handle_softirqs+0xd6/0x2c0 [ 0.946369] ? handle_edge_irq+0xc1/0

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages7 packages

NVDlinux/linux_kernel6.96.12.64+2
Debianlinux/linux_kernel< 6.12.69-1+1
CVEListV5linux/linux1dfc2e46117e5c41037e27e859e75a7518881ee6f5b7f49bd2377916ad57cbd1210c61196daff013+3
debiandebian/linux< linux 6.18.5-1 (forky)

Patches

🔴Vulnerability Details

2
OSV
CVE-2025-71156: In the Linux kernel, the following vulnerability has been resolved: gve: defer interrupt enabling until NAPI registration Currently, interrupts are au2026-01-23
GHSA
GHSA-xfmh-3cc9-8vq3: In the Linux kernel, the following vulnerability has been resolved: gve: defer interrupt enabling until NAPI registration Currently, interrupts are2026-01-23

📋Vendor Advisories

5
Ubuntu
Linux kernel (GCP) vulnerabilities2026-04-17
Ubuntu
Linux kernel (Real-time) vulnerabilities2026-04-17
Ubuntu
Linux kernel vulnerabilities2026-04-16
Red Hat
kernel: Linux kernel (gve): Denial of Service due to premature interrupt enabling2026-01-23
Debian
CVE-2025-71156: linux - In the Linux kernel, the following vulnerability has been resolved: gve: defer ...2025

🕵️Threat Intelligence

1
Wiz
CVE-2025-71156 Impact, Exploitability, and Mitigation Steps | Wiz