Medium severity5.5NVD Advisory· Published May 27, 2026· Updated Jun 25, 2026
CVE-2025-71308
CVE-2025-71308
Description
In the Linux kernel, the following vulnerability has been resolved:
accel/amdxdna: Fix potential NULL pointer dereference in context cleanup
aie_destroy_context() is invoked during error handling in aie2_create_context(). However, aie_destroy_context() assumes that the context's mailbox channel pointer is non-NULL. If mailbox channel creation fails, the pointer remains NULL and calling aie_destroy_context() can lead to a NULL pointer dereference.
In aie2_create_context(), replace aie_destroy_context() with a function which request firmware to remove the context created previously.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9- osv-coords7 versionspkg:apk/chainguard/linux-gcp-6.18pkg:apk/chainguard/linux-gcp-6.18-bootcpkg:apk/chainguard/linux-gcp-6.18-bootc-boot-installedpkg:apk/chainguard/linux-qemu-6.18pkg:apk/chainguard/linux-qemu-6.18-bootcpkg:apk/chainguard/linux-qemu-6.18-bootc-boot-installedpkg:linux/kernel
< 0+ 6 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 6.18.38-r2
- (no CPE)range: < 0
- (no CPE)range: < 6.18.44-r1
- (no CPE)range: < 6.18.38-r2
- (no CPE)range: >= 6.14.0, < 6.19.4
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.