PT-2026-37450 · Linux · Linux Kernel
CVE-2025-71285
·
Published
2026-05-06
·
Updated
2026-08-30
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A race condition exists between client drivers and the MHI stack due to the
auto queue feature, which automatically queues buffers for the RX path (DL channel). This can cause the dl callback() function for the DL channel to be triggered before the client driver is fully probed, potentially leading to a NULL pointer dereference if the driver's structures are not yet initialized. This issue has been observed on Qcom X1E80100 CRD machines, where it affects the boot process.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel