cbcvebase.
CVE-2025-71188
published 2026-01-31

CVE-2025-71188: In the Linux kernel, the following vulnerability has been resolved: dmaengine: lpc18xx-dmamux: fix device leak on route allocation Make sure to drop the…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
8.1th percentile
In the Linux kernel, the following vulnerability has been resolved: dmaengine: lpc18xx-dmamux: fix device leak on route allocation Make sure to drop the reference taken when looking up the DMA mux platform device during route allocation. Note that holding a reference to a device does not prevent its driver data from going away so there is no point in keeping the reference.

Affected

65 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.18.8-1 (forky)linux 6.18.8-1 (forky)
linuxlinux
linuxlinux>= e5f4ae84be7421010780984bdc121eac15997327 < 3d396ebfb3049a2b5fac51d2c967db5114b685e83d396ebfb3049a2b5fac51d2c967db5114b685e8
linuxlinux>= e5f4ae84be7421010780984bdc121eac15997327 < 499ddae78c4baa9b94df76b2d2eb6b150d15377f499ddae78c4baa9b94df76b2d2eb6b150d15377f
linuxlinux>= e5f4ae84be7421010780984bdc121eac15997327 < adef147a8d8c3d767abf88ad2c381ffab2993086adef147a8d8c3d767abf88ad2c381ffab2993086
linuxlinux>= e5f4ae84be7421010780984bdc121eac15997327 < 9fba97baa520c9446df51a64708daf27c5a7ed329fba97baa520c9446df51a64708daf27c5a7ed32
linuxlinux>= e5f4ae84be7421010780984bdc121eac15997327 < 992eb8055a6e5dbb808672d20d68e60d5a89b12b992eb8055a6e5dbb808672d20d68e60d5a89b12b
linuxlinux>= e5f4ae84be7421010780984bdc121eac15997327 < 1e47d80f6720f0224efd19bcf081d39637569c101e47d80f6720f0224efd19bcf081d39637569c10
linuxlinux>= e5f4ae84be7421010780984bdc121eac15997327 < d4d63059dee7e7cae0c4d9a532ed558bc90efb55d4d63059dee7e7cae0c4d9a532ed558bc90efb55
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.18.8-16.18.8-1
linuxlinux_kernel>= 4.3.0 < 5.10.2495.10.249
linuxlinux_kernel>= 4.3.1 < 5.10.2495.10.249
linuxlinux_kernel>= 5.11 < 5.15.1995.15.199
linuxlinux_kernel>= 5.11.0 < 5.15.1995.15.199
linuxlinux_kernel>= 5.16 < 6.1.1626.1.162
linuxlinux_kernel>= 5.16.0 < 6.1.1626.1.162
linuxlinux_kernel>= 6.13 < 6.18.76.18.7
linuxlinux_kernel>= 6.13.0 < 6.18.76.18.7
linuxlinux_kernel>= 6.2 < 6.6.1226.6.122
linuxlinux_kernel>= 6.2.0 < 6.6.1226.6.122
linuxlinux_kernel>= 6.7 < 6.12.676.12.67
linuxlinux_kernel>= 6.7.0 < 6.12.676.12.67
ubuntulinux

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.