CVE-2025-71135

In the Linux kernel, the following vulnerability has been resolved: md/raid5: fix possible null-pointer dereferences in raid5_store_group_thread_cnt() The variable mddev->private is first assigned to conf and then checked: conf = mddev->private; if (!conf) ... If conf is NULL, then mddev->private is also NULL. In this case, null-pointer dereferences can occur when calling raid5_quiesce(): raid5_quiesce(mddev, true); raid5_quiesce(mddev, false); since mddev->private is assigned to conf again in raid5_quiesce(), and conf is dereferenced in several places, for example: conf->quiesce = 0; wake_up(&conf->wait_for_quiescent); To fix this issue, the function should unlock mddev and return before invoking raid5_quiesce() when conf is NULL, following the existing pattern in raid5_change_consistency_policy().
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.13:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc7:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc8:*:*:*:*:*:*

History

17 Jun 2026, 10:03

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: md/raid5: corrige posibles desreferencias de puntero nulo en raid5_store_group_thread_cnt() La variable mddev->private se asigna primero a conf y luego se comprueba: conf = mddev->private; if (!conf) ... Si conf es NULL, entonces mddev->private también es NULL. En este caso, pueden ocurrir desreferencias de puntero nulo al llamar a raid5_quiesce(): raid5_quiesce(mddev, true); raid5_quiesce(mddev, false); ya que mddev->private se asigna a conf de nuevo en raid5_quiesce(), y conf se desreferencia en varios lugares, por ejemplo: conf->quiesce = 0; wake_up(&conf->wait_for_quiescent); Para solucionar este problema, la función debería desbloquear mddev y retornar antes de invocar raid5_quiesce() cuando conf es NULL, siguiendo el patrón existente en raid5_change_consistency_policy().

25 Mar 2026, 18:03

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/20597b7229aea8b5bc45cd92097640257c7fc33b - () https://git.kernel.org/stable/c/20597b7229aea8b5bc45cd92097640257c7fc33b - Patch
References () https://git.kernel.org/stable/c/7ad6ef91d8745d04aff9cce7bdbc6320d8e05fe9 - () https://git.kernel.org/stable/c/7ad6ef91d8745d04aff9cce7bdbc6320d8e05fe9 - Patch
References () https://git.kernel.org/stable/c/e5abb6af905de6b2fead8a0b3f32ab0b81468a01 - () https://git.kernel.org/stable/c/e5abb6af905de6b2fead8a0b3f32ab0b81468a01 - Patch
CPE cpe:2.3:o:linux:linux_kernel:6.19:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc8:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc7:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.13:-:*:*:*:*:*:*
CWE CWE-476
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Linux
Linux linux Kernel

14 Jan 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-14 15:16

Updated : 2026-06-17 10:03


NVD link : CVE-2025-71135

Mitre link : CVE-2025-71135

CVE.ORG link : CVE-2025-71135


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-476

NULL Pointer Dereference