
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-71190 is a device reference leak vulnerability in the Linux kernel's dmaengine: bcm-sba-raid driver. The flaw causes the kernel to fail to drop a reference taken when looking up the mailbox device during probe failures and on driver unbind, resulting in a resource leak. It was published on January 31, 2026, and affects Linux kernel versions from 4.13 through multiple stable branches up to 6.18.6. It carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat CVE, Red Hat Bugzilla).
The root cause is improper resource management (CWE-401: Missing Release of Memory after Effective Lifetime) in the bcm-sba-raid DMA engine driver's probe routine. When the driver calls into the mailbox subsystem to look up a device reference and subsequently encounters a probe failure or is unbound, it does not call the corresponding put_device() (or equivalent) to release the reference, leaving the mailbox device reference count permanently elevated. This is a local, low-complexity issue requiring only low privileges — no user interaction is needed. The fix ensures the reference is properly dropped in all error and unbind paths (Red Hat Bugzilla, Red Hat CVE).
Successful exploitation results in a denial-of-service condition through resource exhaustion: the leaked mailbox device reference prevents proper cleanup, which over repeated probe/unbind cycles can exhaust kernel resources and render the DMA engine device unavailable. There is no impact on confidentiality or integrity (CVSS C:N/I:N/A:H). The scope is limited to the local system and the affected DMA subsystem; lateral movement or data exfiltration are not applicable to this vulnerability (Red Hat CVE).
Update to a patched Linux kernel version immediately. The following stable kernel releases contain the fix: 5.10.249, 5.15.199, 6.1.162, 6.6.122, 6.12.67, 6.18.7, and 6.19-rc6 or later. Patch commits are available in the upstream stable kernel tree. As a workaround on systems that do not require the bcm-sba-raid driver, the module can be blacklisted to prevent loading. Prioritize patching on systems that use Broadcom SBA RAID hardware and rely on this DMA engine driver (Red Hat CVE, Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."