CVE-2025-71185
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-71185 is a device reference leak vulnerability in the Linux kernel's dmaengine: ti: dma-crossbar driver affecting AM335x-based systems. The flaw occurs during route allocation when a reference taken while looking up the crossbar platform device is never released, resulting in a kernel memory leak. It was published on January 31, 2026, and affects Linux kernel versions from 4.4 through multiple stable branches up to 6.18.x and 6.19-rc releases. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-401 (Missing Release of Memory after Effective Lifetime). During AM335x DMA crossbar route allocation, the kernel calls a platform device lookup function that increments a reference count on the crossbar device object, but the corresponding put_device() call to decrement that reference is never made, leaving the reference permanently held. This is a local vulnerability requiring low privileges (e.g., a process that triggers DMA crossbar route allocation), with no user interaction needed. The fix, integrated into stable kernel trees, ensures the reference is properly dropped after the lookup completes (Red Hat Bugzilla, Feedly).

Impact

The primary impact is a denial of service (DoS) condition affecting system availability. Repeated triggering of AM335x DMA crossbar route allocation causes unreleased device references to accumulate, gradually exhausting kernel memory resources and potentially rendering the system unresponsive. There is no confidentiality or integrity impact; the vulnerability is limited to availability degradation on systems using the TI AM335x SoC DMA crossbar hardware (Feedly).

Mitigation and workarounds

Update the Linux kernel to a patched stable version: 5.10.249 or later (for 4.4–5.10 branch), 5.15.199 or later (5.11–5.15), 6.1.162 or later (5.16–6.1), 6.6.122 or later (6.2–6.6), 6.12.67 or later (6.7–6.12), or 6.18.7 or later (6.13+). Ubuntu security notices USN-8162-1, USN-8180-x, USN-8186-1, USN-8188-1, USN-8275-1, USN-8278-x, USN-8289-x, USN-8296-x, USN-8297-1, and USN-8393-1 address this issue for various Ubuntu kernel flavors. As a compensating control, restrict local user access on systems running affected kernels with AM335x DMA crossbar hardware to reduce exposure (Red Hat Bugzilla, Ubuntu USN-8180-1).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management