CVE-2025-71152 Overview
CVE-2025-71152 is a vulnerability in the Linux kernel's Distributed Switch Architecture (DSA) subsystem. The flaw stems from improper reference counting of the conduit net device and its associated kobject. The Open Firmware (OF) probing path calls of_find_net_device_by_node() without releasing the elevated refcount on the conduit's kobject, and DSA can retain a stale cpu_dp->conduit pointer if the conduit interface is unregistered while a switch is being probed. The vulnerability affects Linux kernel versions in the 6.19 release candidate series and has been resolved upstream.
Critical Impact
Local attackers with the ability to bind and unbind network device drivers can trigger reference leaks and use-after-free conditions in DSA-managed network switch code paths, leading to memory corruption and potential privilege escalation.
Affected Products
- Linux Kernel (mainline, up to and including 6.19-rc3)
- Linux Kernel 6.19-rc1
- Linux Kernel 6.19-rc2 and 6.19-rc3
Discovery Timeline
- 2026-01-23 - CVE-2025-71152 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-71152
Vulnerability Analysis
The DSA subsystem manages Ethernet switches attached to a host CPU through a conduit interface. Two distinct defects exist in the reference handling of that conduit net device.
First, the OF probing path uses of_find_net_device_by_node() to look up the conduit but never releases the elevated kobject refcount. The non-OF path dsa_dev_to_net_device() correctly issues put_device(), but the OF path dsa_port_parse_of() omits the matching release. Testing with CONFIG_DEBUG_KOBJECT_RELEASE=y and unbinding the conduit driver confirms the leaked references are only released after the patch.
Second, DSA holds no protection against the conduit interface being unregistered between probe time and user port creation. The subsystem retains a long-lived but potentially stale cpu_dp->conduit pointer. Holding the underlying kobject only prevents the memory from being freed; it does not prevent the netdev itself from being unregistered. The fix runs of_find_net_device_by_node() under rtnl_lock() and acquires a reference through the netdev tracker mechanism (dev_hold() / dev_put()) before releasing the lock.
Root Cause
The root cause is asymmetric reference management between the OF and non-OF conduit lookup paths, combined with a race window during switch probing. The DSA code conflates kobject lifetime with netdev registration lifetime. These are independent concerns, and preventing the kobject from being freed does not stop the netdev from being unregistered and leaving DSA with a dangling pointer.
Attack Vector
Exploitation requires local access with the ability to bind and unbind PCI or platform drivers, typically root or a user with CAP_SYS_ADMIN. An attacker triggers the race by unbinding the conduit interface driver (for example, echo 0000:00:00.2 > /sys/bus/pci/drivers/fsl_enetc/unbind) during or after DSA switch probing. The stale cpu_dp->conduit pointer can then be dereferenced by subsequent DSA operations that traverse from the CPU port to the conduit net device, resulting in use-after-free memory corruption.
The vulnerability manifests in the DSA conduit reference-tracking logic within net/dsa/. See the upstream commits linked in the kernel git history for the full technical details of the fix.
Detection Methods for CVE-2025-71152
Indicators of Compromise
- Kernel oops or panic traces referencing DSA symbols such as dsa_tree_find_first_conduit, cpu_dp->conduit, or netdev operations on freed memory.
- Unexpected kobject_release messages for network interfaces when CONFIG_DEBUG_KOBJECT_RELEASE=y is enabled, indicating leaked references.
- Unusual driver unbind activity through /sys/bus/pci/drivers/*/unbind or /sys/bus/platform/drivers/*/unbind on systems using DSA switches.
Detection Strategies
- Audit kernel logs (dmesg, journalctl -k) for KASAN reports flagging use-after-free conditions in DSA code paths.
- Monitor for repeated driver bind/unbind sequences on network interface drivers, which can indicate an attempt to trigger the race.
- Track kernel version and build metadata across the fleet to identify hosts running vulnerable 6.19-rc kernels.
Monitoring Recommendations
- Enable KASAN and CONFIG_DEBUG_KOBJECT_RELEASE in test kernels to catch reference leaks early in staging.
- Forward kernel telemetry and audit logs to a centralized analytics tier for anomaly detection on sysfs write events targeting driver bind interfaces.
- Alert on any process with CAP_SYS_ADMIN writing to /sys/bus/*/drivers/*/unbind on production hosts that host DSA-managed switches.
How to Mitigate CVE-2025-71152
Immediate Actions Required
- Update to a Linux kernel build that includes the upstream fix commits referenced in the vendor advisory.
- Restrict write access to /sys/bus/pci/drivers/*/unbind and /sys/bus/platform/drivers/*/unbind to trusted administrators only.
- Inventory systems running Linux 6.19 release candidate kernels and prioritize them for patching, particularly embedded and networking appliances that rely on DSA.
Patch Information
The fix is available in the upstream Linux kernel through the following commits: 06e219f6a706, 0e766b77ba50, b358fc6ff3b3, and ec2b34acb189. Distribution vendors will backport these commits to their supported kernel branches. Rebuild and reboot affected hosts after applying the patch.
Workarounds
- Where patching is not immediately feasible, avoid deploying kernels from the 6.19-rc series in production environments.
- Reduce local attack surface by limiting shell access to network appliances that use DSA-managed switches.
- Disable or unload the DSA subsystem on systems that do not require Ethernet switch functionality.
# Verify running kernel version and confirm whether DSA is in use
uname -r
lsmod | grep dsa
# Restrict driver unbind access to root only (example udev rule)
echo 'SUBSYSTEM=="pci", ACTION=="add", RUN+="/bin/chmod 0600 /sys/bus/pci/drivers/fsl_enetc/unbind"' \
> /etc/udev/rules.d/99-restrict-dsa-unbind.rules
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
