CVE-2025-71070 describes a reference count leak in the Linux kernel's ublk subsystem, specifically affecting the UBLK_F_USER_COPY data copy mode. This vulnerability occurs when a ublk server process exits, leaving uncompleted requests with leaked reference counts, leading to incorrect user copy operations and triggering warnings. While a previous fix addressed similar issues for other ublk modes, this patch extends the fix to cover all reference-counted data copy modes, ensuring proper cleanup. The severity of this vulnerability is moderate, with a FAUCET Risk Score of 39/100 and no assigned CVSS score, suggesting a limited direct attack vector. The impact primarily involves system instability and potential data integrity issues due to incorrect memory management rather than direct remote code execution or privilege escalation. The complexity appears to be internal to the kernel's ublk module. There is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. However, the CVE has garnered significant community discussion with 10 mentions, indicating awareness and interest within the cybersecurity community, although it has not received media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.14.6, < 6.15CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS data has not been published for this CVE.
Linux kernel (Raspberry Pi) vulnerabilities
May 7, 2026Linux kernel vulnerabilities
May 7, 2026Linux kernel vulnerabilities
Apr 23, 2026Linux kernel (GCP) vulnerabilities
Apr 17, 2026Linux kernel vulnerabilities
Apr 16, 2026kernel: ublk: clean up user copy references on ublk server exit
Jan 13, 2026