CVE-2025-71313

In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: Add missing NULL check for alloc_workqueue() alloc_workqueue() can return NULL on memory allocation failure. Without proper error checking, this may lead to a NULL pointer dereference when queue_work() is later called with the NULL workqueue pointer in epf_ntb_epc_init(). Add a NULL check immediately after alloc_workqueue() and return -ENOMEM on failure to prevent the driver from loading with an invalid workqueue pointer.
Configurations

Configuration 1 (hide)

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

22 Jul 2026, 19:10

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: PCI: endpoint: Añadir comprobación de NULL faltante para alloc_workqueue() alloc_workqueue() puede devolver NULL en caso de fallo de asignación de memoria. Sin una comprobación de errores adecuada, esto puede llevar a una desreferencia de puntero NULL cuando queue_work() es llamado posteriormente con el puntero de workqueue NULL en epf_ntb_epc_init(). Añadir una comprobación de NULL inmediatamente después de alloc_workqueue() y devolver -ENOMEM en caso de fallo para evitar que el controlador se cargue con un puntero de workqueue inválido.

09 Jun 2026, 20:35

Type Values Removed Values Added
First Time Linux linux Kernel
Linux
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE CWE-476
References () https://git.kernel.org/stable/c/03f336a869b3a3f119d3ae52ac9723739c7fb7b6 - () https://git.kernel.org/stable/c/03f336a869b3a3f119d3ae52ac9723739c7fb7b6 - Patch
References () https://git.kernel.org/stable/c/314eab6740bcda504ef978be599f805de05ce6de - () https://git.kernel.org/stable/c/314eab6740bcda504ef978be599f805de05ce6de - Patch

03 Jun 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-03 18:16

Updated : 2026-07-22 19:10


NVD link : CVE-2025-71313

Mitre link : CVE-2025-71313

CVE.ORG link : CVE-2025-71313


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-476

NULL Pointer Dereference