cbcvebase.
CVE-2025-71186
published 2026-01-31

CVE-2025-71186: In the Linux kernel, the following vulnerability has been resolved: dmaengine: stm32: dmamux: fix device leak on route allocation Make sure to drop the…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
8.5th percentile
In the Linux kernel, the following vulnerability has been resolved: dmaengine: stm32: dmamux: fix device leak on route allocation Make sure to drop the reference taken when looking up the DMA mux platform device during route allocation. Note that holding a reference to a device does not prevent its driver data from going away so there is no point in keeping the reference.

Affected

76 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= df7e762db5f6c8dbd9e480f1c9ef9851de346657 < 3b42020e6790a5e19b36c187ed5b488a5716f97f3b42020e6790a5e19b36c187ed5b488a5716f97f
linuxlinux>= df7e762db5f6c8dbd9e480f1c9ef9851de346657 < 6393da54dcb3488c080a183c4182ddec71ba8d7f6393da54dcb3488c080a183c4182ddec71ba8d7f
linuxlinux>= df7e762db5f6c8dbd9e480f1c9ef9851de346657 < 1dda2a32303df0091896b01a9d09070d61fa344c1dda2a32303df0091896b01a9d09070d61fa344c
linuxlinux>= df7e762db5f6c8dbd9e480f1c9ef9851de346657 < 1a179ac01ff3993ab97e33cc77c316ed7415cda11a179ac01ff3993ab97e33cc77c316ed7415cda1
linuxlinux>= df7e762db5f6c8dbd9e480f1c9ef9851de346657 < 2fb10259d4efb4367787b5ae9c94192e8a91c6482fb10259d4efb4367787b5ae9c94192e8a91c648
linuxlinux>= df7e762db5f6c8dbd9e480f1c9ef9851de346657 < 3ef52d31cce8ba816739085a61efe07b63c6cf273ef52d31cce8ba816739085a61efe07b63c6cf27
linuxlinux>= df7e762db5f6c8dbd9e480f1c9ef9851de346657 < dd6e4943889fb354efa3f700e42739da9bddb6efdd6e4943889fb354efa3f700e42739da9bddb6ef
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.8-16.18.8-1
linuxlinux_kernel>= 4.15.0 < 5.10.2495.10.249
linuxlinux_kernel>= 4.15.1 < 5.10.2495.10.249

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.