CVE-2025-71190: dmaengine: bcm-sba-raid: fix device leak on probe
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: bcm-sba-raid: fix device leak on probe
Make sure to drop the reference taken when looking up the mailbox device
during probe on probe failures and on driver unbind.
Security readout for executives and security teams
Plain-English summary
CVE-2025-71190 is a Linux kernel bug in the bcm-sba-raid DMA engine driver. A device reference may not be released after failed driver probing or unbinding, causing a resource leak. Public sources do not provide a CVSS score, confirmed exploitation, or broad impact statement.
Executive priority
Treat as routine-to-targeted patching unless your environment uses affected Linux kernels with this driver or Siemens products named by vendor advisories. There is no source-confirmed active exploitation in the provided materials.
Technical view
The fix ensures the bcm-sba-raid driver drops the mailbox device reference acquired during probe when probe fails and during driver unbind. The affected component is in the Linux kernel dmaengine subsystem. The CVE record lists Linux kernel versions as affected, with multiple stable kernel commits referenced as fixes.
Likely exposure
Exposure appears limited to Linux systems with kernels containing the affected bcm-sba-raid driver path and relevant hardware or driver activity. Siemens advisories also reference the CVE, so affected industrial products should be checked directly against Siemens guidance.
Exploitation context
No CISA KEV entry is indicated, and the provided sources do not report active exploitation or public exploit availability. The described issue is a resource leak triggered around probe failure or driver unbind, not a clearly documented remote attack path.
Researcher notes
The public record lacks CVSS, CWE, and exploitability analysis. The defect is a device reference leak in bcm-sba-raid probe/unbind handling. Validate against exact kernel branch fixes because the source bundle lists multiple stable commits and version entries.
Mitigation direction
Apply vendor kernel updates that include the referenced stable fixes.
Check Siemens advisories if Siemens products are in scope.
Track Linux distribution advisories for packaged kernel availability.
If no update exists, follow vendor-specific risk guidance.
Validation and detection
Inventory Linux kernel versions across affected assets.
Check whether bcm-sba-raid support is present or enabled.
Confirm installed kernels include the relevant stable fix commit.
Review Siemens advisory applicability for deployed Siemens products.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2025-71190 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.