CVE-2025-71190
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-71190 is a device reference leak vulnerability in the Linux kernel's dmaengine: bcm-sba-raid driver. The flaw causes the kernel to fail to drop a reference taken when looking up the mailbox device during probe failures and on driver unbind, resulting in a resource leak. It was published on January 31, 2026, and affects Linux kernel versions from 4.13 through multiple stable branches up to 6.18.6. It carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat CVE, Red Hat Bugzilla).

Technical details

The root cause is improper resource management (CWE-401: Missing Release of Memory after Effective Lifetime) in the bcm-sba-raid DMA engine driver's probe routine. When the driver calls into the mailbox subsystem to look up a device reference and subsequently encounters a probe failure or is unbound, it does not call the corresponding put_device() (or equivalent) to release the reference, leaving the mailbox device reference count permanently elevated. This is a local, low-complexity issue requiring only low privileges — no user interaction is needed. The fix ensures the reference is properly dropped in all error and unbind paths (Red Hat Bugzilla, Red Hat CVE).

Impact

Successful exploitation results in a denial-of-service condition through resource exhaustion: the leaked mailbox device reference prevents proper cleanup, which over repeated probe/unbind cycles can exhaust kernel resources and render the DMA engine device unavailable. There is no impact on confidentiality or integrity (CVSS C:N/I:N/A:H). The scope is limited to the local system and the affected DMA subsystem; lateral movement or data exfiltration are not applicable to this vulnerability (Red Hat CVE).

Mitigation and workarounds

Update to a patched Linux kernel version immediately. The following stable kernel releases contain the fix: 5.10.249, 5.15.199, 6.1.162, 6.6.122, 6.12.67, 6.18.7, and 6.19-rc6 or later. Patch commits are available in the upstream stable kernel tree. As a workaround on systems that do not require the bcm-sba-raid driver, the module can be blacklisted to prevent loading. Prioritize patching on systems that use Broadcom SBA RAID hardware and rely on this DMA engine driver (Red Hat CVE, Red Hat Bugzilla).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management