CVE-2025-71307
Last modified
CVE-2025-71307 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix NULL pointer dereference on panthor_fw_unplug This patch removes the MCU halt and wait for halt procedures during panthor_fw_unplug() as the MCU can be in a variety of states or the FW may not even be loaded/initialized at all, the latter of which can lead to a NULL pointer dereference. It should be safe on unplug to just disable the MCU without waiting for it to halt as it may not be able to.. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix NULL pointer dereference on panthor_fw_unplug This patch removes the MCU halt and wait for halt procedures during panthor_fw_unplug() as the MCU can be in a variety of states or the FW may not even be loaded/initialized at all, the latter of which can lead to a NULL pointer dereference. It should be safe on unplug to just disable the MCU without waiting for it to halt as it may not be able to.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.19, < 6.19.4 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-71307?
How severe is CVE-2025-71307?
How do I fix CVE-2025-71307?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-71301In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-71302In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-71303In the Linux kernel, the following vulnerability has been re…4.7
- CVE-2025-71304In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-71305In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-71306In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2025-71308In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-71309In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-7131A vulnerability was found in Campcodes Payroll Management Sy…9.8
- CVE-2025-71310The GDPR cookies module for Backdrop CMS (before 1.x-1.3.5…1.8
- CVE-2025-71311In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-71312In the Linux kernel, the following vulnerability has been re…5.5
Are you affected by CVE-2025-71307?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
