CVE-2025-71202
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-71202 is a Linux kernel vulnerability involving the failure to invalidate stale IOTLB (Input/Output Translation Lookaside Buffer) entries for the kernel address space before kernel page table pages are freed and reused. The flaw exists in the IOMMU/SVA (Shared Virtual Addressing) subsystem and is particularly triggered by common memory deallocation operations such as vfree(), which can be initiated by unprivileged local users. Affected versions span Linux kernel 4.4 through 6.18.6. It carries a CVSS v3.1 base score of 5.5 (Medium), with availability impact rated High (Feedly).

Technical details

The root cause is improper management of IOTLB paging cache entries (related to CWE-459: Incomplete Cleanup) in the Linux kernel's IOMMU/SVA subsystem on x86 architecture. When kernel page table pages are freed and reused — a common occurrence during vfree() — the IOMMU is not notified to flush stale paging cache entries for the kernel address space, leading to potential use of stale translations. The fix introduces a new IOMMU interface to flush IOTLB paging cache entries for the CPU kernel address space, invoked from x86 architecture code managing combined user and kernel page tables before any kernel page table page is freed. An extremely rare edge case involving memory unplug of reserved boot memory remains unaddressed but cannot be triggered by unprivileged users (Feedly, Kernel Patch 1, Kernel Patch 2).

Impact

Successful exploitation allows an unprivileged local attacker to trigger system instability and denial of service conditions by causing stale IOTLB entries to persist after kernel page table pages are freed and reused. The primary impact is on availability (rated High), with no confidentiality or integrity impact. The vulnerability is most relevant to systems with SVA enabled on x86 architecture running Linux kernel versions 4.4 through 6.18.6 (Feedly).

Mitigation and workarounds

Update the Linux kernel to version 6.18.7 or later, which includes the fix for this vulnerability. Patch commits are available at the kernel stable repository. Organizations should audit their kernel version inventory and prioritize patching systems with SVA enabled on x86 architecture, as these are most directly affected. No configuration-based workaround is documented; upgrading is the recommended remediation (Feedly, Kernel Patch 1, Kernel Patch 2).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management