Junglewise Threat Intelligence

CVE-2025-71288: Linux Kernel MediaTek SMI memory leak in mtk-smi driver

CVE-2025-71288 · Severity: medium · CVSS 5.5 · Published 2026-05-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's MediaTek Smart Multimedia Interface (SMI) driver could allow a local user to cause a system resource leak. The issue occurs when the system fails to properly release memory references during certain hardware initialization or driver removal processes. Over time, this could lead to memory exhaustion, potentially causing system instability or a crash.

Technical details

A reference counting vulnerability (CWE-401) exists in the MediaTek SMI driver (drivers/memory/mtk-smi.c) within the Linux kernel. The mtk_smi_larb_probe and mtk_smi_common_remove functions fail to call put_device() on the SMI common device reference after it has been looked up. This occurs specifically during late probe failures (such as probe deferral) and during driver unbind operations. A local attacker could potentially exploit this to cause a kernel memory leak, leading to a denial-of-service condition via resource exhaustion. Patches have been released for multiple stable kernel branches including 6.1, 6.6, 6.12, 6.18, and 6.19.

Affected products

  • Linux Linux Kernel 5.16 to 6.1.167, 6.2 to 6.6.130, 6.7 to 6.12.77, 6.13 to 6.18.17, 6.19 to 6.19.6

Timeline

  • 2025-11-21: other: Patch authored
  • 2026-05-06: disclosed: CVE published

References

Related threats