PatchSiren cyber security CVE debrief
CVE-2025-71307 Linux CVE debrief
A NULL pointer dereference vulnerability exists in the Linux kernel's drm/panthor driver during GPU unplug operations. The issue occurs in `panthor_fw_unplug()` when the driver attempts to halt and wait for the Microcontroller Unit (MCU) to stop, but the firmware may not be loaded or initialized. This leads to a NULL pointer dereference because the code assumes valid firmware state that doesn't exist. The vulnerability is triggered during device removal/unplug scenarios where the MCU can be in various states or completely uninitialized. The fix removes the MCU halt and wait procedures from the unplug path, allowing safe device disablement without requiring a responsive MCU. This is a local vulnerability affecting systems with Mali Panthor GPU hardware.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-27
- Original CVE updated
- 2026-05-27
- Advisory published
- 2026-05-27
- Advisory updated
- 2026-05-27
Who should care
Organizations running Linux systems with ARM Mali Panthor GPUs, particularly those using GPU passthrough, hot-plug configurations, or virtualized GPU environments where device removal may occur. Kernel maintainers and distributions packaging drm/panthor driver updates.
Technical summary
The drm/panthor driver in the Linux kernel contains a NULL pointer dereference vulnerability in the `panthor_fw_unplug()` function. The driver attempts to halt the MCU and wait for halt completion during GPU unplug operations, but this assumes the firmware is loaded and initialized. When the firmware is not initialized, the code dereferences a NULL pointer. The vulnerability is local and requires physical or logical access to trigger GPU removal. The fix removes the MCU halt and wait procedures from the unplug path, making it safe to disable the MCU without requiring it to be in a haltable state. This affects systems with ARM Mali Panthor GPUs.
Defensive priority
medium
Recommended defensive actions
- Apply kernel updates containing the drm/panthor fix for CVE-2025-71307 when available from your Linux distribution
- Monitor stable kernel releases from kernel.org for the referenced commits
- For systems with Mali Panthor GPUs, plan maintenance windows to update kernel before physical GPU hot-unplug operations
- Review system logs for GPU-related errors that may indicate trigger conditions
- If running custom kernels, cherry-pick the referenced stable commits to prevent NULL pointer dereference during device removal
Evidence notes
The vulnerability description and resolution are sourced from the official CVE record published 2026-05-27. The fix involves removing MCU halt procedures from `panthor_fw_unplug()` to prevent NULL pointer dereference when firmware is not initialized. Two kernel.org stable tree commits are referenced as resolution sources.
Official resources
-
CVE-2025-71307 CVE record
CVE.org
-
CVE-2025-71307 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
2026-05-27