CVE-2025-71071
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-71071 is a use-after-free vulnerability in the Linux kernel's MediaTek IOMMU driver (iommu/mediatek) that can lead to memory corruption, system instability, or privilege escalation. The flaw was published on January 13, 2026, and affects multiple Linux kernel stable branches: 6.0.16 through 6.0.x, 6.1.2 through 6.1.159, 6.2.1 through 6.6.119, 6.7 through 6.12.63, and 6.13 through 6.18.2. It carries a CVSS v3.1 base score of 7.8 (High) (Feedly, kernel.org patches).

Technical details

The root cause is improper reference counting (CWE-416: Use After Free) in the MediaTek IOMMU driver. During device probe, the driver drops references to larb (local arbiter) devices both after a successful lookup and on error paths. If a larb device has not yet been bound to its driver at probe time, the IOMMU driver defers its probe — but the already-dropped reference leaves a dangling pointer that can be accessed later, constituting a use-after-free condition. The fix retains the device references for the lifetime of the IOMMU driver binding, ensuring the memory remains valid. Exploitation requires local access with low privileges (AV:L/AC:L/PR:L) and no user interaction (Feedly, kernel.org patches).

Impact

Successful exploitation could result in high confidentiality, integrity, and availability impact on the affected system. A local attacker with low privileges could trigger memory corruption in the IOMMU subsystem, potentially escalating privileges, causing kernel panics or system crashes, or corrupting data processed through the MediaTek IOMMU. The vulnerability is scoped to the local system and primarily affects embedded or mobile platforms using MediaTek IOMMU controllers, where device driver binding timing is variable (Feedly).

Mitigation and workarounds

Patches have been released across multiple Linux kernel stable branches. Administrators should update to the following fixed versions: 6.1.160+, 6.6.120+, 6.12.64+, or 6.18.3+, corresponding to upstream commits 1ef70a0b, 5c04217d, 896ec55d, de83d461, and f6c08d3a (kernel.org patches). Downstream distributions including Ubuntu (USN-8177-1, USN-8177-2, USN-8183-1, USN-8183-2, USN-8245-1, USN-8257-1) and SUSE have also issued updated kernel packages (Ubuntu Advisory). As a temporary workaround, restricting local user access on systems with MediaTek IOMMU hardware reduces exposure until patches can be applied (Feedly).

Community reactions

The vulnerability has been addressed by multiple Linux distributions including Ubuntu and SUSE, which have issued kernel security advisories. No notable independent researcher commentary or significant social media discussion has been identified beyond standard distribution security notices (Ubuntu Advisory).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management