PCI: endpoint: Avoid creating sub-groups asynchronously
Published Feb 18, 2026
5.5
MEDIUMCVSS 3.1
EPSS 0.12%
Description
The asynchronous creation of sub-groups by a delayed work could lead to a NULL pointer dereference when the driver directory is removed before the work completes.
The crash can be easily reproduced with the following commands:
# cd /sys/kernel/config/pci_ep/functions/pci_epf_test # for i in {1..20}; do mkdir test && rmdir test; done
BUG: kernel NULL pointer dereference, address: 0000000000000088 ... Call Trace: configfs_register_group+0x3d/0x190 pci_epf_cfs_work+0x41/0x110 process_one_work+0x18f/0x350 worker_thread+0x25a/0x3a0
Fix this issue by using configfs_add_default_group() API which does not have the deadlock problem as configfs_register_group() and does not require the delayed work handler.
[mani: slightly reworded the description and added stable list]
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.12StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.12
- Version 5.15.201StatusunaffectedConstraints<=5.15.*
- Version 6.1.164StatusunaffectedConstraints<=6.1.*
- Version 6.12.72StatusunaffectedConstraints<=6.12.*
- Version 6.18.11StatusunaffectedConstraints<=6.18.*
- Version 6.19.1StatusunaffectedConstraints<=6.19.*
- Version 6.6.127StatusunaffectedConstraints<=6.6.*
- Version 7.0StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 5.12 · < 5.15.201
- ≥ 5.16 · < 6.1.164
- ≥ 6.2 · < 6.6.127
- ≥ 6.7 · < 6.12.72
- ≥ 6.13 · < 6.18.11
- ≥ 6.19 · < 6.19.1
No data.
Red Hat Enterprise Linux 10
kernel
Fix deferred
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
A NULL pointer dereference can occur in the PCI endpoint configfs code because sub groups were created asynchronously using delayed work. If a user removes the driver directory before the delayed work runs the work handler can call configfs_register_group on freed or partially torn down objects and crash the kernel. For the CVSS the PR is H because writing to configfs and creating PCI endpoint function entries typically requires administrative privileges. The issue is not network reachable and is triggered by local filesystem operations on configfs entries. Impact is denial of service through a kernel crash and there is no clear indication of confidentiality or integrity impact from this NULL dereference.
References (13)
- https://access.redhat.com/security/cve/CVE-2025-71233 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2440667 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-207665 Advisory
- https://git.kernel.org/stable/c/24a253c3aa6d9a2cde46158ce9782e023bfbf32d Patch
- https://git.kernel.org/stable/c/5f609b3bffd4207cf9f2c9b41e1978457a5a1ea9 Patch
- https://git.kernel.org/stable/c/73cee890adafa2c219bb865356e08e7f82423fe5 Patch
- https://git.kernel.org/stable/c/7c5c7d06bd1f86d2c3ebe62be903a4ba42db4d2c Patch
- https://git.kernel.org/stable/c/8cb905eca73944089a0db01443c7628a9e87012d Patch
- https://git.kernel.org/stable/c/d9af3cf58bb4c8d6dea4166011c780756b1138b5 Patch
- https://git.kernel.org/stable/c/fa9fb38f5fe9c80094c2138354d45cdc8d094d69 Patch
- https://lore.kernel.org/linux-cve-announce/2026021805-CVE-2025-71233-0c35@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2025-71233
- https://www.cve.org/CVERecord?id=CVE-2025-71233
Change history (0)
No recorded changes yet.