cbcvebase.
CVE-2025-71189
published 2026-01-31

CVE-2025-71189: In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw: dmamux: fix OF node leak on route allocation failure Make sure to drop the…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
8.1th percentile
In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw: dmamux: fix OF node leak on route allocation failure Make sure to drop the reference taken to the DMA master OF node also on late route allocation failures.

Affected

58 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 134d9c52fca26d2d199516e915da00f0cc6adc73 < 6b87288581a0fcbe54b39da5c10e1aee2df8776e6b87288581a0fcbe54b39da5c10e1aee2df8776e
linuxlinux>= 134d9c52fca26d2d199516e915da00f0cc6adc73 < db7c79c1bbfb1b0184e78a17ac2bd0f2bc3134d1db7c79c1bbfb1b0184e78a17ac2bd0f2bc3134d1
linuxlinux>= 134d9c52fca26d2d199516e915da00f0cc6adc73 < 8f7a391211381ed2f6802032c78c7820d166bc498f7a391211381ed2f6802032c78c7820d166bc49
linuxlinux>= 134d9c52fca26d2d199516e915da00f0cc6adc73 < eabe40f8a53c29f531e92778ea243e379f4f7978eabe40f8a53c29f531e92778ea243e379f4f7978
linuxlinux>= 134d9c52fca26d2d199516e915da00f0cc6adc73 < ec25e60f9f95464aa11411db31d0906b3fb7b9f2ec25e60f9f95464aa11411db31d0906b3fb7b9f2
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.8-16.18.8-1
linuxlinux_kernel>= 5.19.0 < 6.1.1626.1.162
linuxlinux_kernel>= 5.19.1 < 6.1.1626.1.162
linuxlinux_kernel>= 6.13 < 6.18.76.18.7
linuxlinux_kernel>= 6.13.0 < 6.18.76.18.7
linuxlinux_kernel>= 6.2 < 6.6.1226.6.122

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.