CVE-2025-71071
HIGHLinux Kernel < 6.1.160, 6.2.0-6.12.64, 6.7.0-6.18.3 - Use-After-Free in IOMMU Mediatek Driver
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: iommu/mediatek: fix use-after-free on probe deferral The driver is dropping the references taken to the larb devices during probe after successful lookup as well as on errors. This can potentially lead to a use-after-free in case a larb device has not yet been bound to its driver so that the iommu driver probe defers. Fix this by keeping the references as expected while the iommu driver is bound.
References (5)
Core 5
Core References
Scores
CVSS v3
7.8
EPSS
0.0002
EPSS Percentile
6.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-416
Status
published
Products (21)
linux/Kernel
< 6.1.160linux
linux/Kernel
6.2.0 - 6.12.64linux
linux/Kernel
6.7.0 - 6.18.3linux
Linux/Linux
< 6.2
Linux/Linux
26593928564cf5b576ff05d3cbd958f57c9534bb - 1ef70a0b104ae8011811f60bcfaa55ff49385171
Linux/Linux
26593928564cf5b576ff05d3cbd958f57c9534bb - 5c04217d06a1161aaf36267e9d971ab6f847d5a7
Linux/Linux
26593928564cf5b576ff05d3cbd958f57c9534bb - de83d4617f9fe059623e97acf7e1e10d209625b5
Linux/Linux
26593928564cf5b576ff05d3cbd958f57c9534bb - f6c08d3aa441bbc1956e9d65f1cbb89113a5aa8a
Linux/Linux
51080de72e26771f0ed9d44982974279ccbc92b8
Linux/Linux
6.0.16 - 6.1
... and 11 more
Published
Jan 13, 2026
Tracked Since
Feb 18, 2026