IM
IronMonkey Threat Research

CVE-2025-71186 MEDIUM

Published: 2026-01-31 | Last Modified: 2026-07-14 | Status: Modified

Description

In the Linux kernel, the following vulnerability has been resolved: dmaengine: stm32: dmamux: fix device leak on route allocation Make sure to drop the reference taken when looking up the DMA mux platform device during route allocation. Note that holding a reference to a device does not prevent its driver data from going away so there is no point in keeping the reference.

Additional Descriptions (1)

En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: dmaengine: stm32: dmamux: corregir fuga de dispositivo en la asignación de ruta Asegúrese de liberar la referencia tomada al buscar el dispositivo de plataforma DMA mux durante la asignación de ruta. Tenga en cuenta que mantener una referencia a un dispositivo no evita que los datos de su controlador desaparezcan, por lo que no tiene sentido mantener la referencia.

CVSS Metrics

Base Score: 5.5 (MEDIUM)

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack VectorLOCAL
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 1.8

Impact Score: 3.6

Weaknesses

Source Type Description
[email protected] Primary
en CWE-401

Affected Products

Vendor Product Version Update Type
linux linux_kernel * <built-in method update of dict object at 0x7cc9c413b340> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7cc9c413bb40> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7cc9c4139800> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7cc9c4138780> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7cc9c413bdc0> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7cc9c413a880> Operating System
linux linux_kernel 4.15 <built-in method update of dict object at 0x7cc9c4138c00> Operating System
linux linux_kernel 6.19 <built-in method update of dict object at 0x7cc9c4138d00> Operating System
linux linux_kernel 6.19 <built-in method update of dict object at 0x7cc9c41391c0> Operating System
linux linux_kernel 6.19 <built-in method update of dict object at 0x7cc9c41388c0> Operating System
linux linux_kernel 6.19 <built-in method update of dict object at 0x7cc9c4138580> Operating System
linux linux_kernel 6.19 <built-in method update of dict object at 0x7cc9c4138cc0> Operating System
linux linux_kernel 6.19 <built-in method update of dict object at 0x7cc9e1a24140> Operating System
linux linux_kernel 6.19 <built-in method update of dict object at 0x7cc9fb935940> Operating System
linux linux_kernel 6.19 <built-in method update of dict object at 0x7cc9a35f9280> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:4.15:-:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.19:rc1:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.19:rc2:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.19:rc3:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.19:rc4:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.19:rc5:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.19:rc6:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.19:rc7:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.19:rc8:*:*:*:*:*:*

References

Notification
Message here