# CVE-2025-71221

## Summary

- **CVE ID:** CVE-2025-71221
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Feb 14, 2026
- **Last Modified:** Sep 8, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue()

Add proper locking in mmp_pdma_residue() to prevent use-after-free when
accessing descriptor list and descriptor contents.

The race occurs when multiple threads call tx_status() while the tasklet
on another CPU is freeing completed descriptors:

CPU 0                              CPU 1
-----                              -----
mmp_pdma_tx_status()
mmp_pdma_residue()
  -> NO LOCK held
     list_for_each_entry(sw, ..)
                                   DMA interrupt
                                   dma_do_tasklet()
                                     -> spin_lock(&desc_lock)
                                        list_move(sw->node, ...)
                                        spin_unlock(&desc_lock)
  |                                     dma_pool_free(sw) <- FREED!
  -> access sw->desc <- UAF!

This issue can be reproduced when running dmatest on the same channel with
multiple threads (threads_per_chan > 1).

Fix by protecting the chain_running list iteration and descriptor access
with the chan->desc_lock spinlock.

## Affected Products

- Linux — Linux (1b38da264674d6a0fe26a63996b8f88b88c3da48)
- Linux — Linux (3.16)
- Linux — Linux (0)
- Linux — Linux (6.18.10)
- Linux — Linux (6.19)
- Linux — Linux (6.1.167)
- Linux — Linux (6.6.130)
- Linux — Linux (6.12.78)
- Linux — Linux (5.15.209)

## References

- [CNA](https://git.kernel.org/stable/c/9f665b3c3d9a168410251f27a5d019b7bf93185c)
- [CNA](https://git.kernel.org/stable/c/a143545855bc2c6e1330f6f57ae375ac44af00a7)
- [CNA](https://git.kernel.org/stable/c/dfb5e05227745de43b7fd589721817a4337c970d)
- [CNA](https://git.kernel.org/stable/c/eba0c75670c022cb1f948600db972524bcfe8166)
- [CNA](https://git.kernel.org/stable/c/fc023b8fab057f0c910856ff36d3e12a30b7af4a)
- [CNA](https://git.kernel.org/stable/c/3f0e0e2d9e752570041e95fd04635e2580097819)
- [siemens-SADP](https://cert-portal.siemens.com/productcert/html/ssa-082556.html)
- [siemens-SADP](https://cert-portal.siemens.com/productcert/html/ssa-019113.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.10%
- **EPSS Percentile:** 1.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._