CVE-2025-71083

medium

Description

In the Linux kernel, the following vulnerability has been resolved: drm/ttm: Avoid NULL pointer deref for evicted BOs It is possible for a BO to exist that is not currently associated with a resource, e.g. because it has been evicted. When devcoredump tries to read the contents of all BOs for dumping, we need to expect this as well -- in this case, ENODATA is recorded instead of the buffer contents.

References

https://git.kernel.org/stable/c/b94182b3d7228aec18d069cba56d5982e9bfe1b1

https://git.kernel.org/stable/c/5a81095d3e1b521ac7cfe3b14d5f149bace3d6e0

https://git.kernel.org/stable/c/4b9944493c6d92d7b29cfd83aaf3deb842b8da79

https://git.kernel.org/stable/c/491adc6a0f9903c32b05f284df1148de39e8e644

https://git.kernel.org/stable/c/3d004f7341d4898889801ebb2ef61ffca610dd6f

Details

Source: Mitre, NVD

Published: 2026-01-13

Updated: 2026-01-14

Risk Information

CVSS v2

Base Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00018