
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-71138 is a NULL pointer dereference vulnerability in the Linux kernel's DRM MSM DPU (Display Processing Unit) driver, specifically within the dpu_encoder_phys_wb_setup_ctl() function where a NULL check for the pingpong interface is missing in one code path despite being present elsewhere. It affects Linux kernel versions 5.19, 5.19.1 through 6.6.120, 6.7 through 6.12.64, 6.13 through 6.18.4, and 6.19 release candidates (rc1–rc8). The vulnerability was published on January 14, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 5.5 (Medium) (Feedly, NVD).
The root cause is classified as CWE-476 (NULL Pointer Dereference). In dpu_encoder_phys_wb_setup_ctl(), the pingpong interface pointer is validated with a NULL check in nearly all code paths, but one specific path omits this check, allowing a NULL dereference if the interface is not initialized. Exploitation requires local access with low privileges; an attacker can trigger the vulnerable code path through display/writeback encoder operations on affected Qualcomm MSM hardware. No public proof-of-concept exploit code has been identified (Feedly, NVD).
Successful exploitation causes a kernel NULL pointer dereference, resulting in a kernel panic and denial of service (system crash). The impact is limited to availability — there is no confidentiality or integrity impact. The vulnerability affects systems running Qualcomm MSM display hardware with the DPU driver loaded, and does not enable lateral movement or data exfiltration (Feedly).
Patches are available via the Linux kernel stable tree. Apply the fixes targeting the following version boundaries: upgrade to 6.6.120 or later (for 5.19.1–6.6.x), 6.12.64 or later (for 6.7–6.12.x), or 6.18.4 or later (for 6.13–6.18.x). Microsoft also released a patch for the Azure Linux 3 kernel (azl3_kernel_6.6.119.3-3) on January 16, 2026. As a workaround, limiting local user access on systems with Qualcomm MSM display hardware reduces exposure. Monitor for unexpected kernel crashes on affected systems as a precautionary measure (Feedly, kernel.org patch).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."