CVE-2025-71233 is a NULL pointer dereference vulnerability in the Linux kernel's PCI endpoint subsystem. It occurs when asynchronous sub-group creation, handled by a delayed work, attempts to access a driver directory that has been removed, leading to a system crash. The vulnerability is easily reproducible with specific commands, indicating a low attack complexity. While no CVSS score is available, its FAUCET Risk Score is 16/100, suggesting a moderate risk. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) exists. However, the vulnerability has garnered some community attention and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.12, < 5.15.201CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.1.164CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.6.127CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.12.72CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.13, < 6.18.11CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Azure CVM) vulnerabilities
Jul 24, 2026Linux kernel vulnerabilities
Jul 24, 2026Linux kernel (Azure CVM) vulnerabilities
Jul 24, 2026Linux kernel (Azure CVM) vulnerabilities
Jul 24, 2026Linux kernel (Azure) vulnerabilities
Jul 24, 2026Linux kernel vulnerabilities
Jul 21, 2026Linux kernel (FIPS) vulnerabilities
Jul 10, 2026Linux kernel (Raspberry Pi Real-time) vulnerabilities
Jul 6, 2026Linux kernel (Xilinx) vulnerabilities
Jul 2, 2026Linux kernel (Low Latency) vulnerabilities
Jul 2, 2026Linux kernel vulnerabilities
Jul 2, 2026Linux kernel vulnerabilities
Jul 1, 2026kernel: Linux kernel: Denial of Service via NULL pointer dereference in PCI endpoint configfs during asynchronous sub-group creation
Feb 18, 2026PCI: endpoint: Avoid creating sub-groups asynchronously
Feb 10, 2026