Junglewise Threat Intelligence

CVE-2025-71162: Linux Kernel Tegra ADMA use-after-free in audio termination

CVE-2025-71162 · Severity: high · CVSS 7.8 · Published 2026-01-25

Technologies: Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A security vulnerability exists in the Linux kernel's Tegra ADMA driver, which manages audio data transfers for specific hardware. When audio playback is stopped or interrupted, a race condition can occur where the system attempts to access memory that has already been cleared. This could allow a local attacker to cause a system crash or potentially gain unauthorized access to sensitive information or elevated privileges.

Technical details

A use-after-free vulnerability exists in the tegra-adma dmaengine driver due to a race condition between DMA termination and completion tasklets. When tegra_adma_terminate_all() is called (e.g., during audio XRUN conditions), it frees the DMA descriptor memory via kfree(). However, if a completion interrupt has already scheduled a tasklet, vchan_complete() may subsequently attempt to access that freed memory. The fix involves using vchan_terminate_vdesc() to mark descriptors as terminated and implementing a synchronization callback to ensure pending tasklets are killed before memory is released. This is a local vulnerability requiring low privileges to exploit.

Affected products

  • Linux Linux Kernel Tegra ADMA driver support introduced in f46b195799b5
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6
  • Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP V3.1.6
  • Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP V3.1.6

Timeline

  • 2025-11-10: disclosed: Initial patch submitted by NVIDIA
  • 2025-12-16: patched: Merged into mainline kernel tree
  • 2026-01-25: advisory: NVD publication date

References

Related threats