CVE-2025-71071

HIGH

Linux Kernel < 6.1.160, 6.2.0-6.12.64, 6.7.0-6.18.3 - Use-After-Free in IOMMU Mediatek Driver

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: iommu/mediatek: fix use-after-free on probe deferral The driver is dropping the references taken to the larb devices during probe after successful lookup as well as on errors. This can potentially lead to a use-after-free in case a larb device has not yet been bound to its driver so that the iommu driver probe defers. Fix this by keeping the references as expected while the iommu driver is bound.

Scores

CVSS v3 7.8
EPSS 0.0002
EPSS Percentile 6.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-416
Status published
Products (21)
linux/Kernel < 6.1.160linux
linux/Kernel 6.2.0 - 6.12.64linux
linux/Kernel 6.7.0 - 6.18.3linux
Linux/Linux < 6.2
Linux/Linux 26593928564cf5b576ff05d3cbd958f57c9534bb - 1ef70a0b104ae8011811f60bcfaa55ff49385171
Linux/Linux 26593928564cf5b576ff05d3cbd958f57c9534bb - 5c04217d06a1161aaf36267e9d971ab6f847d5a7
Linux/Linux 26593928564cf5b576ff05d3cbd958f57c9534bb - de83d4617f9fe059623e97acf7e1e10d209625b5
Linux/Linux 26593928564cf5b576ff05d3cbd958f57c9534bb - f6c08d3aa441bbc1956e9d65f1cbb89113a5aa8a
Linux/Linux 51080de72e26771f0ed9d44982974279ccbc92b8
Linux/Linux 6.0.16 - 6.1
... and 11 more
Published Jan 13, 2026
Tracked Since Feb 18, 2026