memory: mtk-smi: fix device leak on larb probe
Summary
| CVE | CVE-2025-71287 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-06 12:16:27 UTC |
| Updated | 2026-05-13 18:42:19 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: memory: mtk-smi: fix device leak on larb probe Make sure to drop the reference taken when looking up the SMI device during larb probe on late probe failure (e.g. probe deferral) and on driver unbind. |
Risk And Classification
Primary CVSS: v3.1 5.5 MEDIUM from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Problem Types: CWE-401
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected cc8bbe1a83128ad06457e4dc69907c4f9a6fc1a7 04057b86fdac3d4847913a97dc6552c0bff9b85e git | Not specified |
| CNA | Linux | Linux | affected cc8bbe1a83128ad06457e4dc69907c4f9a6fc1a7 357e16a7fc9c1fef2ea37dce9bb6b9bcb1d1687d git | Not specified |
| CNA | Linux | Linux | affected cc8bbe1a83128ad06457e4dc69907c4f9a6fc1a7 b9eccd59697f7e1cb9a714501d9af826e7f7e073 git | Not specified |
| CNA | Linux | Linux | affected cc8bbe1a83128ad06457e4dc69907c4f9a6fc1a7 1f23a48ff2b8ab47e514f7c84a4b1dbf9b848168 git | Not specified |
| CNA | Linux | Linux | affected cc8bbe1a83128ad06457e4dc69907c4f9a6fc1a7 f69535b77fa0518ad39870c00dd2995439ed5c34 git | Not specified |
| CNA | Linux | Linux | affected cc8bbe1a83128ad06457e4dc69907c4f9a6fc1a7 1288bb394d464975cea18f69940f206e235e0fe7 git | Not specified |
| CNA | Linux | Linux | affected cc8bbe1a83128ad06457e4dc69907c4f9a6fc1a7 9dae65913b32d05dbc8ff4b8a6bf04a0e49a8eb6 git | Not specified |
| CNA | Linux | Linux | affected 4.6 | Not specified |
| CNA | Linux | Linux | unaffected 4.6 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.203 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.167 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.130 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.77 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.17 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.19.6 6.19.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.0 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/b9eccd59697f7e1cb9a714501d9af826e7f7e073 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/04057b86fdac3d4847913a97dc6552c0bff9b85e | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/1288bb394d464975cea18f69940f206e235e0fe7 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/f69535b77fa0518ad39870c00dd2995439ed5c34 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/1f23a48ff2b8ab47e514f7c84a4b1dbf9b848168 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/9dae65913b32d05dbc8ff4b8a6bf04a0e49a8eb6 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/357e16a7fc9c1fef2ea37dce9bb6b9bcb1d1687d | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.