cbcvebase.
CVE-2025-71233
published 2026-02-18

CVE-2025-71233: In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: Avoid creating sub-groups asynchronously The asynchronous creation of…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.0th percentile
In the Linux kernel, the following vulnerability has been resolved:

PCI: endpoint: Avoid creating sub-groups asynchronously

The asynchronous creation of sub-groups by a delayed work could lead to a
NULL pointer dereference when the driver directory is removed before the
work completes.

The crash can be easily reproduced with the following commands:

# cd /sys/kernel/config/pci_ep/functions/pci_epf_test
# for i in {1..20}; do mkdir test && rmdir test; done

BUG: kernel NULL pointer dereference, address: 0000000000000088
...
Call Trace:
configfs_register_group+0x3d/0x190
pci_epf_cfs_work+0x41/0x110
process_one_work+0x18f/0x350
worker_thread+0x25a/0x3a0

Fix this issue by using configfs_add_default_group() API which does not
have the deadlock problem as configfs_register_group() and does not require
the delayed work handler.

[mani: slightly reworded the description and added stable list]

Affected

61 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
debianlinux-6.1< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
linuxlinux
linuxlinux>= e85a2d7837622bd99c96f5bbc7f972da90c285a2 < fa9fb38f5fe9c80094c2138354d45cdc8d094d69fa9fb38f5fe9c80094c2138354d45cdc8d094d69
linuxlinux>= e85a2d7837622bd99c96f5bbc7f972da90c285a2 < 5f609b3bffd4207cf9f2c9b41e1978457a5a1ea95f609b3bffd4207cf9f2c9b41e1978457a5a1ea9
linuxlinux>= e85a2d7837622bd99c96f5bbc7f972da90c285a2 < 8cb905eca73944089a0db01443c7628a9e87012d8cb905eca73944089a0db01443c7628a9e87012d
linuxlinux>= e85a2d7837622bd99c96f5bbc7f972da90c285a2 < d9af3cf58bb4c8d6dea4166011c780756b1138b5d9af3cf58bb4c8d6dea4166011c780756b1138b5
linuxlinux>= e85a2d7837622bd99c96f5bbc7f972da90c285a2 < 24a253c3aa6d9a2cde46158ce9782e023bfbf32d24a253c3aa6d9a2cde46158ce9782e023bfbf32d
linuxlinux>= e85a2d7837622bd99c96f5bbc7f972da90c285a2 < 73cee890adafa2c219bb865356e08e7f82423fe573cee890adafa2c219bb865356e08e7f82423fe5
linuxlinux>= e85a2d7837622bd99c96f5bbc7f972da90c285a2 < 7c5c7d06bd1f86d2c3ebe62be903a4ba42db4d2c7c5c7d06bd1f86d2c3ebe62be903a4ba42db4d2c
linuxlinux_kernel>= 0 < 6.1.164-16.1.164-1
linuxlinux_kernel>= 0 < 6.12.73-16.12.73-1
linuxlinux_kernel>= 0 < 6.18.12-16.18.12-1
linuxlinux_kernel>= 5.12 < 5.15.2015.15.201
linuxlinux_kernel>= 5.16 < 6.1.1646.1.164
linuxlinux_kernel>= 6.13 < 6.18.116.18.11
linuxlinux_kernel>= 6.19 < 6.19.16.19.1
linuxlinux_kernel>= 6.2 < 6.6.1276.6.127
linuxlinux_kernel>= 6.7 < 6.12.726.12.72
msrcazl3_kernel_6.6.121.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.126.1-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu8.8HIGH
vendor_msrc8.4HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.