LiveActive security incident?Get immediate response
CVE Record

CVE-2025-71190: dmaengine: bcm-sba-raid: fix device leak on probe

In the Linux kernel, the following vulnerability has been resolved: dmaengine: bcm-sba-raid: fix device leak on probe Make sure to drop the reference taken when looking up the mailbox device during probe on probe failures and on driver unbind.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

CVE-2025-71190 is a Linux kernel bug in the bcm-sba-raid DMA engine driver. A device reference may not be released after failed driver probing or unbinding, causing a resource leak. Public sources do not provide a CVSS score, confirmed exploitation, or broad impact statement.

Executive priority

Treat as routine-to-targeted patching unless your environment uses affected Linux kernels with this driver or Siemens products named by vendor advisories. There is no source-confirmed active exploitation in the provided materials.

Technical view

The fix ensures the bcm-sba-raid driver drops the mailbox device reference acquired during probe when probe fails and during driver unbind. The affected component is in the Linux kernel dmaengine subsystem. The CVE record lists Linux kernel versions as affected, with multiple stable kernel commits referenced as fixes.

Likely exposure

Exposure appears limited to Linux systems with kernels containing the affected bcm-sba-raid driver path and relevant hardware or driver activity. Siemens advisories also reference the CVE, so affected industrial products should be checked directly against Siemens guidance.

Exploitation context

No CISA KEV entry is indicated, and the provided sources do not report active exploitation or public exploit availability. The described issue is a resource leak triggered around probe failure or driver unbind, not a clearly documented remote attack path.

Researcher notes

The public record lacks CVSS, CWE, and exploitability analysis. The defect is a device reference leak in bcm-sba-raid probe/unbind handling. Validate against exact kernel branch fixes because the source bundle lists multiple stable commits and version entries.

Mitigation direction

  • Apply vendor kernel updates that include the referenced stable fixes.
  • Check Siemens advisories if Siemens products are in scope.
  • Track Linux distribution advisories for packaged kernel availability.
  • If no update exists, follow vendor-specific risk guidance.

Validation and detection

  • Inventory Linux kernel versions across affected assets.
  • Check whether bcm-sba-raid support is present or enabled.
  • Confirm installed kernels include the relevant stable fix commit.
  • Review Siemens advisory applicability for deployed Siemens products.
Prepared
Confidence
medium
Sources
11

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2025-71190 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
2ADP providers
10Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

siemens-SADPADP container
CISA-ADPCISA ADP Vulnrichment
other:ssvc
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux743e1c8ffe4ee5dd7596556dcc3f022ccde13d7b, 743e1c8ffe4ee5dd7596556dcc3f022ccde13d7b, 743e1c8ffe4ee5dd7596556dcc3f022ccde13d7b, 743e1c8ffe4ee5dd7596556dcc3f022ccde13d7b, 743e1c8ffe4ee5dd7596556dcc3f022ccde13d7b, 743e1c8ffe4ee5dd7596556dcc3f022ccde13d7b, 743e1c8ffe4ee5dd7596556dcc3f022ccde13d7bunaffected
LinuxLinux4.13, 0, 5.10.249, 5.15.199, 6.1.162, 6.6.122, 6.12.67, 6.18.7, 6.19affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.