cbcvebase.
CVE-2025-71221
published 2026-02-14

CVE-2025-71221: In the Linux kernel, the following vulnerability has been resolved: dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue() Add proper locking in…

PriorityP431high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.10%
0.8th percentile
In the Linux kernel, the following vulnerability has been resolved: dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue() Add proper locking in mmp_pdma_residue() to prevent use-after-free when accessing descriptor list and descriptor contents. The race occurs when multiple threads call tx_status() while the tasklet on another CPU is freeing completed descriptors: CPU 0 CPU 1 ----- ----- mmp_pdma_tx_status() mmp_pdma_residue() -> NO LOCK held list_for_each_entry(sw, ..) DMA interrupt dma_do_tasklet() -> spin_lock(&desc_lock) list_move(sw->node, ...) spin_unlock(&desc_lock) | dma_pool_free(sw) access sw->desc 1). Fix by protecting the chain_running list iteration and descriptor access with the chan->desc_lock spinlock.

Affected

53 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.18.10-1 (forky)linux 6.18.10-1 (forky)
linuxlinux
linuxlinux>= 1b38da264674d6a0fe26a63996b8f88b88c3da48 < 3f0e0e2d9e752570041e95fd04635e25800978193f0e0e2d9e752570041e95fd04635e2580097819
linuxlinux>= 1b38da264674d6a0fe26a63996b8f88b88c3da48 < dfb5e05227745de43b7fd589721817a4337c970ddfb5e05227745de43b7fd589721817a4337c970d
linuxlinux>= 1b38da264674d6a0fe26a63996b8f88b88c3da48 < eba0c75670c022cb1f948600db972524bcfe8166eba0c75670c022cb1f948600db972524bcfe8166
linuxlinux>= 1b38da264674d6a0fe26a63996b8f88b88c3da48 < fc023b8fab057f0c910856ff36d3e12a30b7af4afc023b8fab057f0c910856ff36d3e12a30b7af4a
linuxlinux>= 1b38da264674d6a0fe26a63996b8f88b88c3da48 < 9f665b3c3d9a168410251f27a5d019b7bf93185c9f665b3c3d9a168410251f27a5d019b7bf93185c
linuxlinux>= 1b38da264674d6a0fe26a63996b8f88b88c3da48 < a143545855bc2c6e1330f6f57ae375ac44af00a7a143545855bc2c6e1330f6f57ae375ac44af00a7
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.18.10-16.18.10-1
linuxlinux_kernel>= 3.16 < 6.18.106.18.10
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-5.15
ubuntulinux-azure-6.8
ubuntulinux-azure-fde
ubuntulinux-azure-fde-5.15

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.0HIGH
vendor_ubuntu7.1HIGH
vendor_debian7.0HIGH
vendor_msrc7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.