Medium severity5.5NVD Advisory· Published Jun 3, 2026· Updated Jul 22, 2026
CVE-2025-71313
CVE-2025-71313
Description
In the Linux kernel, the following vulnerability has been resolved:
PCI: endpoint: Add missing NULL check for alloc_workqueue()
alloc_workqueue() can return NULL on memory allocation failure. Without proper error checking, this may lead to a NULL pointer dereference when queue_work() is later called with the NULL workqueue pointer in epf_ntb_epc_init().
Add a NULL check immediately after alloc_workqueue() and return -ENOMEM on failure to prevent the driver from loading with an invalid workqueue pointer.
Affected products
10- osv-coords7 versionspkg:apk/chainguard/linux-gcp-6.18pkg:apk/chainguard/linux-gcp-6.18-bootcpkg:apk/chainguard/linux-gcp-6.18-bootc-boot-installedpkg:apk/chainguard/linux-qemu-6.18pkg:apk/chainguard/linux-qemu-6.18-bootcpkg:apk/chainguard/linux-qemu-6.18-bootc-boot-installedpkg:linux/kernel
< 0+ 6 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 6.18.38-r2
- (no CPE)range: < 0
- (no CPE)range: < 6.18.44-r1
- (no CPE)range: < 6.18.38-r2
- (no CPE)range: >= 5.12.0, < 6.19.4
Patches
Vulnerability mechanics
References
2News mentions
1- Google Android and Linux Kernel: 50 Vulnerabilities Disclosed in Two BatchesVypr Intelligence · Jun 3, 2026