Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-71122— iommufd/selftest: Check for overflow in IOMMU_TEST_OP_ADD_RESERVED

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于测试代码中未验证用户输入长度,可能导致整数溢出和区间树损坏。

AI Predicted 5.5 Difficulty: Hard EPSS 0.19% · P9

Possible ATT&CK Techniques 1 AI

T1068 · Exploitation for Privilege Escalation

Affected Version Matrix 10

VendorProduct Version RangeStatus
Linux Linux f4b20bb34c83dceade5470288f48f94ce3598ada< 4cc829d61f10c20523fd4085c1546e741a792a97 affected
f4b20bb34c83dceade5470288f48f94ce3598ada< e6c122cffcbb2e84d321ec8ba0e38ce8e7c10925 affected
f4b20bb34c83dceade5470288f48f94ce3598ada< b166b8e0a381429fefd9180e67fbc834b3cee82f affected
f4b20bb34c83dceade5470288f48f94ce3598ada< e6a973af11135439de32ece3b9cbe3bfc043bea8 affected
6.2 affected
< 6.2 unaffected
6.6.120≤ 6.6.* unaffected
6.12.64≤ 6.12.* unaffected
… +2 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-71122

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
iommufd/selftest: Check for overflow in IOMMU_TEST_OP_ADD_RESERVED
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: iommufd/selftest: Check for overflow in IOMMU_TEST_OP_ADD_RESERVED syzkaller found it could overflow math in the test infrastructure and cause a WARN_ON by corrupting the reserved interval tree. This only effects test kernels with CONFIG_IOMMUFD_TEST. Validate the user input length in the test ioctl.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于测试代码中未验证用户输入长度,可能导致整数溢出和区间树损坏。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux f4b20bb34c83dceade5470288f48f94ce3598ada ~ 4cc829d61f10c20523fd4085c1546e741a792a97 -
Linux Linux 6.2 -

II. Public POCs for CVE-2025-71122

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-71122

登录查看更多情报信息。

Same Patch Batch · Linux · 2026-01-14 · 43 CVEs total

CVE-2025-71116 9.1 CRITICAL libceph: make decode_pool() more resilient against corrupted osdmaps
CVE-2025-71112 8.8 HIGH net: hns3: add VLAN id validation before using
CVE-2025-71130 7.8 HIGH drm/i915/gem: Zero-initialize the eb.vma array in i915_gem_do_execbuffer
CVE-2025-71120 7.5 HIGH SUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token in gss_read_proxy_verf
CVE-2025-71126 7.5 HIGH mptcp: avoid deadlock on fallback while reinjecting
CVE-2025-71128 7.5 HIGH erspan: Initialize options_len before referencing options.
CVE-2025-71131 7.5 HIGH crypto: seqiv - Do not use req->iv after crypto_aead_encrypt
CVE-2025-71132 7.5 HIGH smc91x: fix broken irq-context in PREEMPT_RT
CVE-2025-71127 7.1 HIGH wifi: mac80211: Discard Beacon frames to non-broadcast address
CVE-2025-71136 7.1 HIGH media: adv7842: Avoid possible out-of-bounds array accesses in adv7842_cp_log_status()
CVE-2025-71109 7.1 HIGH MIPS: ftrace: Fix memory corruption when kernel is located beyond 32 bits
CVE-2025-71111 hwmon: (w83791d) Convert macros to functions to avoid TOCTOU
CVE-2025-71110 mm/slub: reset KASAN tag in defer_free() before accessing freed memory
CVE-2025-71104 KVM: x86: Fix VM hard lockup after prolonged inactivity with periodic HV timer
CVE-2025-71114 via_wdt: fix critical boot hang due to unnamed resource allocation
CVE-2025-71115 um: init cpu_tasks[] earlier
CVE-2025-71103 drm/msm: adreno: fix deferencing ifpc_reglist when not declared
CVE-2025-71117 block: Remove queue freezing from several sysfs store callbacks
CVE-2025-71102 scs: fix a wrong parameter in __scs_magic
CVE-2025-71105 f2fs: use global inline_xattr_slab instead of per-sb slab cache

Showing top 20 of 43 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-71122

Anonymous User
2026-01-15 06:08:14

Zaproxy alias impedit expedita quisquam pariatur exercitationem. Nemo rerum eveniet dolores rem quia dignissimos.


Leave a comment