CVE-2025-71186
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-71186 is a device reference leak vulnerability in the Linux kernel's DMA engine STM32 DMAMUX driver. During route allocation, the driver fails to drop the reference taken when looking up the DMA mux platform device, resulting in a resource leak (CWE-401). The vulnerability affects Linux kernel versions from 4.15 through multiple stable branches, with fixed versions including 5.10.249, 5.15.199, 6.1.162, 6.6.122, 6.12.67, and 6.18.7. It was published on January 31, 2026, and carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-401 (Missing Release of Memory after Effective Lifetime). In the stm32-dmamux driver, when allocating a DMA route, the code calls a platform device lookup function that increments the device reference count, but never calls the corresponding put_device() to release it. As noted in the fix, holding a reference to a device does not prevent its driver data from becoming unavailable, making the retained reference both a leak and functionally useless. The vulnerability requires local access with low privileges to trigger, as it is exercised through normal DMA route allocation operations on affected STM32 hardware (Red Hat Bugzilla, Red Hat Advisory).

Impact

The primary impact is availability degradation through resource exhaustion. As device references accumulate without being released over repeated DMA route allocations, systems may experience gradual memory pressure and instability, particularly in memory-constrained environments or those performing frequent DMA operations. There is no confidentiality or integrity impact; the vulnerability is limited to availability (CVSS A:H, C:N, I:N) (Red Hat Advisory).

Mitigation and workarounds

Update the Linux kernel to a patched version that resolves the STM32 DMAMUX device leak. Fixed versions are available across multiple stable branches: 5.10.249, 5.15.199, 6.1.162, 6.6.122, 6.12.67, 6.18.7, and 6.19-rc6. Patches are available in the upstream kernel stable repository. Ubuntu has issued multiple security notices (USN-8162-1, USN-8180-1 through USN-8180-6, USN-8186-1, USN-8188-1, USN-8275-1, USN-8278-1, USN-8289-1, USN-8296-1, USN-8297-1) addressing this and related kernel vulnerabilities (Red Hat Advisory, Ubuntu USN-8180-1).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management