CVE-2025-71202Patch(linux / linux_kernel)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: iommu/sva: invalidate stale IOTLB entries for kernel address space Introduce a new IOMMU interface to flush IOTLB paging cache entries for the CPU kernel address space. This interface is invoked from the x86 architecture code that manages combined user and kernel page tables, specifically before any kernel page table page is freed and reused. This addresses the main issue with vfree() which is a common occurrence and can be triggered by unprivileged users. While this resolves the primary problem, it doesn't address some extremely rare case related to memory unplug of memory that was present as reserved memory at boot, which cannot be triggered by unprivileged users. The discussion can be found at the link below. Enable SVA on x86 architecture since the IOMMU can now receive notification to flush the paging cache before freeing the CPU kernel page table pages.

0.0/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Patch: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-14); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-14: 1Mentions · 2026-03-18: 1Technical Details · 2026-02-14: 1Technical Details · 2026-03-18: 102-1403-18
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-141
Patch1
2026-03-181
Disclosure1
Full discourse2 posts
  • CVE@CVEnew
    Patch

    CVE-2025-71202 In the Linux kernel, the following vulnerability has been resolved: iommu/sva: invalidate stale IOTLB entries for kernel address space Introduce a new IOMMU interfa… https://www.cve.org/CVERecord?id=CVE-2025-71202

    Post summary

    CVE‑2025‑71202, a kernel IOTLB stale entry flaw, has been fixed, but the post provides only a high‑level statement of resolution without patch specifics or exploit details.

    00010107
    56.4K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 #Linux Kernel, Privilege Escalation, #CVE-2025-71202 (High) https://dailycve.com/linux-kernel-privilege-escalation-cve-2025-71202-high/

    Post summary

    The post announces the Linux Kernel privilege escalation vulnerability CVE-2025-71202 with a high severity rating, but does not disclose any PoC, exploit code, active exploitation, or patch details.

    0000051
    169 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---

Explore more