CVE-2025-71157: Linux Kernel
High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: RDMA/core: always drop device refcount in ib_del_sub_device_and_put() Since nldev_deldev() (introduced by commit 060c642b2ab8 ("RDMA/nldev: Add support to add/delete a sub IB device through netlink") grabs a reference using ib_device_get_by_index() before calling ib_del_sub_device_and_put(), we need to drop that reference before returning -EOPNOTSUPP error.
Affected products
- Linux Linux Kernel: from 6.11, before 6.12.64 (fixed in 6.12.64); from 6.13, before 6.18.4 (fixed in 6.18.4); version 6.19 only
Published 2026-01-23. Last modified 2026-06-17.