iommu/mediatek: fix use-after-free on probe deferral
Published Jan 13, 2026
7.8
HIGHCVSS 3.1
EPSS 0.15%
Description
The driver is dropping the references taken to the larb devices during probe after successful lookup as well as on errors. This can potentially lead to a use-after-free in case a larb device has not yet been bound to its driver so that the iommu driver probe defers.
Fix this by keeping the references as expected while the iommu driver is bound.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints
- Version
-
- Version 6.0.16StatusaffectedConstraints<6.1
- Version 6.1.2StatusaffectedConstraints<6.1.160
- Version
-
- Version 6.2StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.2
- Version 6.1.160StatusunaffectedConstraints<=6.1.*
- Version 6.12.64StatusunaffectedConstraints<=6.12.*
- Version 6.18.3StatusunaffectedConstraints<=6.18.*
- Version 6.19StatusunaffectedConstraints<=*
- Version 6.6.120StatusunaffectedConstraints<=6.6.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 6.0.16 · < 6.1
- ≥ 6.1.2 · < 6.1.160
- ≥ 6.2.1 · < 6.6.120
- ≥ 6.7 · < 6.12.64
- ≥ 6.13 · < 6.18.3
- 6.2
- 6.19
- 6.19
- 6.19
- 6.19
- 6.19
- 6.19
- 6.19
- 6.19
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Jan–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.15% (0.00146) | 3.27th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.13% (0.00125) | 2.53th | v5 (v2026.06.15) |
| Jan 14, 2026 | 0.02% (0.00018) | 3.87th | v4 (v2025.03.14) |
References (10)
- https://access.redhat.com/security/cve/CVE-2025-71071 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2429038 Issue Tracking
- https://git.kernel.org/stable/c/1ef70a0b104ae8011811f60bcfaa55ff49385171 Patch
- https://git.kernel.org/stable/c/5c04217d06a1161aaf36267e9d971ab6f847d5a7 Patch
- https://git.kernel.org/stable/c/896ec55da3b90bdb9fc04fedc17ad8c359b2eee5 Patch
- https://git.kernel.org/stable/c/de83d4617f9fe059623e97acf7e1e10d209625b5 Patch
- https://git.kernel.org/stable/c/f6c08d3aa441bbc1956e9d65f1cbb89113a5aa8a Patch
- https://lore.kernel.org/linux-cve-announce/2026011325-CVE-2025-71071-67e9@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2025-71071
- https://www.cve.org/CVERecord?id=CVE-2025-71071
Change history (0)
No recorded changes yet.