CVE-2025-71081

Source
https://cve.org/CVERecord?id=CVE-2025-71081
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-71081.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-71081
Downstream
Related
Published
2026-01-13T15:34:45.503Z
Modified
2026-05-15T11:53:59.550887319Z
Summary
ASoC: stm32: sai: fix OF node leak on probe
Details

In the Linux kernel, the following vulnerability has been resolved:

ASoC: stm32: sai: fix OF node leak on probe

The reference taken to the sync provider OF node when probing the platform device is currently only dropped if the set_sync() callback fails during DAI probe.

Make sure to drop the reference on platform probe failures (e.g. probe deferral) and on driver unbind.

This also avoids a potential use-after-free in case the DAI is ever reprobed without first rebinding the platform driver.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/71xxx/CVE-2025-71081.json"
}
References

Affected packages

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.15.0
Fixed
5.15.198
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.160
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.120
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.64
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-71081.json"