CVE-2025-71078
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-71078 is a memory management flaw in the Linux kernel's PowerPC 64-bit hash MMU subsystem, specifically in the Software Segment Lookaside Buffer (SLB) preload cache handling. The vulnerability causes SLB multi-hit errors when a process migrates between CPUs under specific context-switching conditions, potentially leading to kernel crashes. It was published on January 13, 2026, and affects Linux kernel versions 4.20.1 through 5.10.247, 5.11 through 5.15.197, 5.16 through 6.1.159, 6.2 through 6.6.119, 6.7 through 6.12.63, 6.13 through 6.18.3, and 6.19-rc1 through rc8. It carries a CVSS v3.1 base score of 7.8 (High) (Feedly).

Technical details

The root cause is a race condition / state desynchronization (related to CWE-362 or improper state management) in switch_mm_irqs_off() on hash MMU PowerPC systems. As a performance optimization, the kernel skips switch_mmu_context() when the previous and next mm_struct are identical. However, the software SLB preload cache is periodically evicted (approximately every 256 context switches), and if an SLB entry is evicted on one CPU while the hardware SLB on another CPU still holds the corresponding entry, a subsequent reload attempt triggers an SLB multi-hit error — a fatal hardware fault on POWER processors. Exploitation requires local access and relies on specific timing involving process migration between CPUs (Feedly, Kernel Patches).

Impact

Successful exploitation causes a kernel panic (SLB multi-hit error) on PowerPC 64-bit systems using the hash MMU, resulting in complete system unavailability (denial of service). The CVSS score also reflects high confidentiality and integrity impacts, suggesting potential for privilege escalation or memory corruption in certain exploitation scenarios. The vulnerability is scoped to PowerPC 64-bit hardware (e.g., IBM POWER servers) and does not affect x86 or ARM architectures (Feedly).

Indicators of compromise

  • Logs: Kernel logs (dmesg or /var/log/kern.log) showing SLB multi-hit machine check exceptions on PowerPC systems, e.g., messages containing SLB multi-hit or Machine check originating from switch_mm_irqs_off or SLB reload paths.
  • System Behavior: Unexpected kernel panics or system reboots on PowerPC 64-bit hosts, particularly under high process migration or context-switching workloads.
  • Process: Unusual system instability correlated with high CPU migration activity of specific processes on multi-CPU PowerPC systems.

Mitigation and workarounds

Apply the patched kernel versions released across stable branches: 5.10.248 or later, 5.15.198 or later, 6.1.160 or later, 6.6.120 or later, 6.12.64 or later, and 6.18.4 or later. Microsoft has also released a patch for Azure Linux kernel version 6.6.119.3-3. Ubuntu security notices USN-8177-1, USN-8177-2, USN-8183-1, USN-8183-2, USN-8245-1, and USN-8257-1 address this issue for affected Ubuntu releases. As an interim measure, restrict local user access on PowerPC 64-bit systems and monitor for unexpected kernel crashes (Feedly, Ubuntu USN-8177-1, Kernel Patches).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management