PT-2026-37450 · Linux · Linux Kernel

CVE-2025-71285

·

Published

2026-05-06

·

Updated

2026-08-30

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A race condition exists between client drivers and the MHI stack due to the auto queue feature, which automatically queues buffers for the RX path (DL channel). This can cause the dl callback() function for the DL channel to be triggered before the client driver is fully probed, potentially leading to a NULL pointer dereference if the driver's structures are not yet initialized. This issue has been observed on Qcom X1E80100 CRD machines, where it affects the boot process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-85826
CVE-2025-71285

Affected Products

Linux Kernel