CVE-2025-71233

Source
https://cve.org/CVERecord?id=CVE-2025-71233
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-71233.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-71233
Downstream
Related
Published
2026-02-18T14:53:17.926Z
Modified
2026-04-02T17:30:09.012059801Z
Summary
PCI: endpoint: Avoid creating sub-groups asynchronously
Details

In the Linux kernel, the following vulnerability has been resolved:

PCI: endpoint: Avoid creating sub-groups asynchronously

The asynchronous creation of sub-groups by a delayed work could lead to a NULL pointer dereference when the driver directory is removed before the work completes.

The crash can be easily reproduced with the following commands:

# cd /sys/kernel/config/pciep/functions/pciepf_test # for i in {1..20}; do mkdir test && rmdir test; done

BUG: kernel NULL pointer dereference, address: 0000000000000088 ... Call Trace: configfsregistergroup+0x3d/0x190 pciepfcfswork+0x41/0x110 processonework+0x18f/0x350 workerthread+0x25a/0x3a0

Fix this issue by using configfsadddefaultgroup() API which does not have the deadlock problem as configfsregister_group() and does not require the delayed work handler.

[mani: slightly reworded the description and added stable list]

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/71xxx/CVE-2025-71233.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e85a2d7837622bd99c96f5bbc7f972da90c285a2
Fixed
fa9fb38f5fe9c80094c2138354d45cdc8d094d69
Fixed
5f609b3bffd4207cf9f2c9b41e1978457a5a1ea9
Fixed
8cb905eca73944089a0db01443c7628a9e87012d
Fixed
d9af3cf58bb4c8d6dea4166011c780756b1138b5
Fixed
24a253c3aa6d9a2cde46158ce9782e023bfbf32d
Fixed
73cee890adafa2c219bb865356e08e7f82423fe5
Fixed
7c5c7d06bd1f86d2c3ebe62be903a4ba42db4d2c

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-71233.json"