CVE-2025-71076 addresses a vulnerability in the Linux kernel's drm/xe/oa component, where the OA open parameters failed to validate the num_syncs value. This allowed unprivileged users to request excessively large memory allocations, potentially leading to system instability or denial of service. While no CVSS score is available, the vulnerability's nature suggests a local attack vector with low complexity, as it involves unchecked user input. There is no evidence of active exploitation, nor are there public exploit modules or proof-of-concept code. However, the vulnerability has garnered some community discussion and media coverage, including a security update from openSUSE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.12.17, < 6.12.64CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.12.17, < 6.12.64CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.13.1, < 6.18.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.13CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.13:-:*:*:*:*:*:* | ||
6.19CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.19:rc1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Raspberry Pi) vulnerabilities
May 7, 2026Linux kernel vulnerabilities
May 7, 2026Linux kernel vulnerabilities
Apr 23, 2026Linux kernel (GCP) vulnerabilities
Apr 17, 2026Linux kernel vulnerabilities
Apr 16, 2026kernel: drm/xe/oa: Limit num_syncs to prevent oversized allocations
Jan 13, 2026