CVE-2025-71103
Linux Ubuntu vulnerability analysis and mitigation

Overview

CVE-2025-71103 is a NULL pointer dereference vulnerability in the Linux kernel's DRM/MSM Adreno GPU driver. On platforms with a7xx GPUs that do not support IFPC (Inline Frame Per-Context), the ifpc_reglist pointer is dereferenced without validation in the a7xx_patch_pwrup_reglist() function, causing a kernel crash. The vulnerability affects Linux kernel versions 6.18.0 through 6.18.2 and 6.19-rc1 through 6.19-rc8. It carries a CVSS v3.1 base score of 5.5 (Medium) (Feedly, kernel.org patch).

Technical details

The root cause is a missing NULL check (CWE-476) in a7xx_patch_pwrup_reglist() within the MSM Adreno GPU driver. When a platform uses an a7xx GPU that does not support IFPC, the ifpc_reglist pointer is never initialized, yet the function proceeds to dereference it to configure power-up register values. This triggers a kernel NULL pointer dereference at virtual address 0x0000000000000008 during GPU hardware initialization, specifically when a DRM file is opened (e.g., during framebuffer device setup). The fix adds a validity check on ifpc_reglist before dereferencing the table (Feedly, Patchwork).

Impact

Successful exploitation causes a kernel panic (denial of service), crashing the affected system. The vulnerability is triggered during normal graphics subsystem initialization — specifically when a user opens a DRM file — making it reachable on any affected system with a qualifying a7xx GPU. There is no confidentiality or integrity impact; the sole consequence is a system crash that renders the device unavailable until rebooted (Feedly).

Mitigation and workarounds

The vulnerability is fixed in Linux kernel version 6.18.3 and later, via commits 129049d4fe22c998ae9fd1ec479fbb4ed5338c15 and 19648135e904bce447d368ecb6136e5da809639c in the stable kernel tree. Users running kernel versions 6.18.0–6.18.2 or 6.19-rc1 through rc8 on systems with a7xx GPUs lacking IFPC support should upgrade immediately. As a temporary workaround where patching is not immediately feasible, restricting GPU access or disabling graphics subsystem initialization may reduce exposure (Feedly, kernel.org patch).

Additional resources


SourceThis report was generated using AI

Related Linux Ubuntu vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-50737CRITICAL9
  • Linux Debian logoLinux Debian
  • pglogical
NoNoJul 28, 2026
CVE-2026-50736CRITICAL9
  • Linux Debian logoLinux Debian
  • pglogical
NoNoJul 28, 2026
CVE-2026-50738HIGH7.7
  • Linux Debian logoLinux Debian
  • pglogical
NoNoJul 28, 2026
CVE-2026-61547NONEN/A
  • Linux Debian logoLinux Debian
  • librabbitmq
NoYesJul 29, 2026
CVE-2026-59986NONEN/A
  • Linux Debian logoLinux Debian
  • librabbitmq
NoYesJul 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management