IM
IronMonkey Threat Research

CVE-2025-71188 MEDIUM

Published: 2026-01-31 | Last Modified: 2026-06-02 | Status: Modified

Description

In the Linux kernel, the following vulnerability has been resolved: dmaengine: lpc18xx-dmamux: fix device leak on route allocation Make sure to drop the reference taken when looking up the DMA mux platform device during route allocation. Note that holding a reference to a device does not prevent its driver data from going away so there is no point in keeping the reference.

Additional Descriptions (1)

En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: dmaengine: lpc18xx-dmamux: corregir fuga de dispositivo en la asignación de ruta Asegúrese de liberar la referencia tomada al buscar el dispositivo de plataforma DMA mux durante la asignación de ruta. Tenga en cuenta que mantener una referencia a un dispositivo no evita que los datos de su controlador desaparezcan, por lo que no tiene sentido mantener la referencia.

CVSS Metrics

Base Score: 5.5 (MEDIUM)

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack VectorLOCAL
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 1.8

Impact Score: 3.6

Weaknesses

Source Type Description
[email protected] Primary
en CWE-401

Affected Products

Vendor Product Version Update Type
linux linux_kernel * <built-in method update of dict object at 0x7b06e9456440> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7b06fe302840> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7b067e054700> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7b070c24c540> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7b06e9455780> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7b06e94547c0> Operating System
linux linux_kernel 4.3 <built-in method update of dict object at 0x7b070c24cc00> Operating System
linux linux_kernel 6.19 <built-in method update of dict object at 0x7b06e9206880> Operating System
linux linux_kernel 6.19 <built-in method update of dict object at 0x7b06e9205000> Operating System
linux linux_kernel 6.19 <built-in method update of dict object at 0x7b06e9455680> Operating System
linux linux_kernel 6.19 <built-in method update of dict object at 0x7b070caa6840> Operating System
linux linux_kernel 6.19 <built-in method update of dict object at 0x7b06e8701d00> Operating System
linux linux_kernel 6.19 <built-in method update of dict object at 0x7b06e87035c0> Operating System
linux linux_kernel 6.19 <built-in method update of dict object at 0x7b072ce81180> Operating System
linux linux_kernel 6.19 <built-in method update of dict object at 0x7b06a5e04880> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:4.3:-:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.19:rc1:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.19:rc2:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.19:rc3:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.19:rc4:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.19:rc5:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.19:rc6:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.19:rc7:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.19:rc8:*:*:*:*:*:*

References

Notification
Message here