CVE-2025-71233

Source
https://cve.org/CVERecord?id=CVE-2025-71233
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-71233.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-71233
Downstream
Related
Published
2026-02-18T14:53:17.926Z
Modified
2026-05-28T03:53:40.771207698Z
Summary
PCI: endpoint: Avoid creating sub-groups asynchronously
Details

In the Linux kernel, the following vulnerability has been resolved:

PCI: endpoint: Avoid creating sub-groups asynchronously

The asynchronous creation of sub-groups by a delayed work could lead to a NULL pointer dereference when the driver directory is removed before the work completes.

The crash can be easily reproduced with the following commands:

# cd /sys/kernel/config/pciep/functions/pciepf_test # for i in {1..20}; do mkdir test && rmdir test; done

BUG: kernel NULL pointer dereference, address: 0000000000000088 ... Call Trace: configfsregistergroup+0x3d/0x190 pciepfcfswork+0x41/0x110 processonework+0x18f/0x350 workerthread+0x25a/0x3a0

Fix this issue by using configfsadddefaultgroup() API which does not have the deadlock problem as configfsregister_group() and does not require the delayed work handler.

[mani: slightly reworded the description and added stable list]

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/71xxx/CVE-2025-71233.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e85a2d7837622bd99c96f5bbc7f972da90c285a2
Fixed
fa9fb38f5fe9c80094c2138354d45cdc8d094d69
Fixed
5f609b3bffd4207cf9f2c9b41e1978457a5a1ea9
Fixed
8cb905eca73944089a0db01443c7628a9e87012d
Fixed
d9af3cf58bb4c8d6dea4166011c780756b1138b5
Fixed
24a253c3aa6d9a2cde46158ce9782e023bfbf32d
Fixed
73cee890adafa2c219bb865356e08e7f82423fe5
Fixed
7c5c7d06bd1f86d2c3ebe62be903a4ba42db4d2c

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-71233.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.12.0
Fixed
5.15.201
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.164
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.127
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.72
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.11
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-71233.json"