CVE-2025-71138
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-71138 is a NULL pointer dereference vulnerability in the Linux kernel's DRM MSM DPU (Display Processing Unit) driver, specifically within the dpu_encoder_phys_wb_setup_ctl() function where a NULL check for the pingpong interface is missing in one code path despite being present elsewhere. It affects Linux kernel versions 5.19, 5.19.1 through 6.6.120, 6.7 through 6.12.64, 6.13 through 6.18.4, and 6.19 release candidates (rc1–rc8). The vulnerability was published on January 14, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 5.5 (Medium) (Feedly, NVD).

Technical details

The root cause is classified as CWE-476 (NULL Pointer Dereference). In dpu_encoder_phys_wb_setup_ctl(), the pingpong interface pointer is validated with a NULL check in nearly all code paths, but one specific path omits this check, allowing a NULL dereference if the interface is not initialized. Exploitation requires local access with low privileges; an attacker can trigger the vulnerable code path through display/writeback encoder operations on affected Qualcomm MSM hardware. No public proof-of-concept exploit code has been identified (Feedly, NVD).

Impact

Successful exploitation causes a kernel NULL pointer dereference, resulting in a kernel panic and denial of service (system crash). The impact is limited to availability — there is no confidentiality or integrity impact. The vulnerability affects systems running Qualcomm MSM display hardware with the DPU driver loaded, and does not enable lateral movement or data exfiltration (Feedly).

Mitigation and workarounds

Patches are available via the Linux kernel stable tree. Apply the fixes targeting the following version boundaries: upgrade to 6.6.120 or later (for 5.19.1–6.6.x), 6.12.64 or later (for 6.7–6.12.x), or 6.18.4 or later (for 6.13–6.18.x). Microsoft also released a patch for the Azure Linux 3 kernel (azl3_kernel_6.6.119.3-3) on January 16, 2026. As a workaround, limiting local user access on systems with Qualcomm MSM display hardware reduces exposure. Monitor for unexpected kernel crashes on affected systems as a precautionary measure (Feedly, kernel.org patch).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management