CVE-2025-71188
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-71188 is a device reference leak vulnerability in the Linux kernel's dmaengine: lpc18xx-dmamux driver. During route allocation, a reference taken when looking up the DMA mux platform device is not properly released, causing a kernel resource leak. The vulnerability affects Linux kernel versions from 4.3 through multiple stable branches, with fixed versions including 5.10.249, 5.15.199, 6.1.162, 6.6.122, 6.12.67, 6.18.7, and 6.19-rc6. It was published on January 31, 2026, and carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-401 (Missing Release of Memory after Effective Lifetime). In the lpc18xx_dmamux_reserve_chan() route allocation path, the kernel calls of_find_device_by_node() or an equivalent platform device lookup that increments the device reference count, but the corresponding put_device() call is never made, leaving the reference dangling. The fix ensures the reference is dropped immediately after the lookup, since holding a device reference does not prevent its driver data from being freed and thus provides no meaningful protection. No public proof-of-concept exploit code is known for this vulnerability (Red Hat Bugzilla, Red Hat Advisory).

Impact

Successful triggering of this vulnerability results in a device reference count leak within the kernel, causing kernel resources to accumulate over time with each route allocation operation. Repeated allocations can lead to memory exhaustion and degradation of system stability or availability, particularly on systems that frequently allocate DMA mux routes. There is no confidentiality or integrity impact; the sole consequence is a potential denial-of-service condition on affected systems using the LPC18xx DMA mux driver (Red Hat Advisory).

Mitigation and workarounds

Update the Linux kernel to a patched version: 5.10.249, 5.15.199, 6.1.162, 6.6.122, 6.12.67, 6.18.7, or 6.19-rc6 (or later), depending on the branch in use. Patch commits are available in the upstream stable kernel repository. Distribution-specific updates have been issued by Ubuntu (USN-8162-1, USN-8180-x series, USN-8186-1, USN-8188-1, USN-8275-1, USN-8278-x, USN-8289-x, USN-8296-x, USN-8297-1, USN-8393-1) and SUSE. Administrators should apply kernel updates from their distribution vendor promptly, particularly on systems using NXP LPC18xx/LPC43xx SoCs with the affected DMA mux driver (Red Hat Advisory, Ubuntu USN-8180).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management