CVE-2025-71095
A flaw in the Linux kernel's network driver (stmmac) causes the system to crash when using specific high-performance networking features. This occurs because the driver incorrectly handles memory types during certain data transmission actions.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users running the Linux kernel, specifically those using the stmmac network driver with zero copy XDP_TX enabled.
Real-world impact
An attacker or a specific network configuration could trigger a kernel panic, causing the entire system to crash and become unavailable.
Why this severity
The critical score is due to the vulnerability being remotely exploitable over a network without requiring authentication or user interaction, leading to a complete system crash (denial of service).
What to do about it
- 01Update the Linux kernel to a version that includes the fix for the stmmac driver.
NVD-referenced vendor advisory
Timeline
- Jan 13, 2026 · Jan 13, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 30, 2026 · 6d agoAdvisory updatedThe NVD record was last revised.
- Jul 30, 2026 · 6d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.