CVE-2025-71163
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-71163 is a memory leak (device reference leak) vulnerability in the Linux kernel's dmaengine: idxd driver. The flaw exists in the compat bind and unbind sysfs interface, where device references acquired during idxd device lookup are not properly released. It was published on January 25, 2026, and affects Linux kernel versions from 5.15 through 6.18.x (prior to their respective fixed releases), as well as 6.19 release candidates up to rc5. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-401 (Missing Release of Memory after Effective Lifetime). When a user-space process interacts with the idxd driver's compatibility (compat) sysfs interface to bind or unbind a device, the kernel takes a reference to the idxd device object for the duration of the lookup but fails to drop that reference upon completion of the operation. This results in a reference count leak for each bind/unbind call. Exploitation requires local access and low privileges — an attacker can repeatedly trigger the compat bind/unbind sysfs operations to accumulate unreleased device references, gradually exhausting kernel memory resources (Red Hat Advisory, Red Hat Bugzilla).

Impact

Successful exploitation leads to progressive memory exhaustion and system resource depletion, resulting in a high availability impact. An attacker with local low-privileged access can degrade or destabilize the affected system by repeatedly triggering the vulnerable sysfs interface, potentially causing kernel memory pressure, idxd driver failures, or broader system instability. There is no confidentiality or integrity impact — the vulnerability is limited to availability (Red Hat Advisory).

Mitigation and workarounds

Patches are available across multiple stable kernel branches. Administrators should upgrade to the following fixed versions or later: Linux kernel 5.15.199, 6.1.162, 6.6.122, 6.12.67, 6.18.7, or 6.19-rc6. Specific upstream fix commits include 0c97ff108f825a70c3bb29d65ddf0a013d231bb9, 799900f01792cf8b525a44764f065f83fcafd468, a7226fd61def74b60dd8e47ec84cabafc39d575b, b2d077180a56e3b7c97b7517d0465b584adc693b, b7bd948f89271c92d9ca9b2b682bfba56896e959, and c81ea0222eaaafdd77348e27d1e84a1b8cfc0c99. As a short-term workaround, restricting local user access to the idxd sysfs interface can reduce the attack surface until patching is feasible (Red Hat Advisory, Red Hat Bugzilla).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management