Junglewise Threat Intelligence

CVE-2025-71188: Linux Kernel resource leak in lpc18xx-dmamux route allocation

CVE-2025-71188 · Severity: medium · CVSS 5.5 · Published 2026-01-31

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's DMA (Direct Memory Access) multiplexer for certain NXP processors could allow a local user to cause a resource leak. This occurs when the system fails to properly release internal references during data routing tasks. Over time, this could lead to system instability or a denial-of-service condition as system resources are exhausted.

Technical details

A resource leak (CWE-401) exists in the dmaengine component of the Linux kernel, specifically within the lpc18xx-dmamux driver. The function `lpc18xx_dmamux_reserve` fails to call `put_device()` after looking up the DMA mux platform device during route allocation. This results in a reference count leak for the device object. An attacker with local access could potentially exploit this to exhaust kernel memory or prevent device unbinding, leading to a denial of service. The issue has been patched in multiple stable branches including 5.10.250, 5.15.200, 6.1.163, 6.6.123, 6.12.68, and 6.18.8.

Affected products

  • Linux Linux Kernel 4.3 to 5.10.249, 5.11 to 5.15.199, 5.16 to 6.1.162, 6.2 to 6.6.122, 6.7 to 6.12.67, 6.13 to 6.18.7

Timeline

  • 2025-01-31: disclosed
  • 2025-01-31: advisory
  • 2026-01-23: patched: Initial patch commit in stable tree

References