Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2025-71199

Published Feb 4, 2026 EPSS 0.17% (7th pctl)

Overview

CVE-2025-71199 is a known-severity vulnerability. It was published on February 4, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

iio: adc: at91-sama5d2_adc: Fix potential use-after-free in sama5d2_adc driver

at91_adc_interrupt can call at91_adc_touch_data_handler function

to start the work by schedule_work(&st->touch_st.workq).

If we remove the module which will call at91_adc_remove to

make cleanup, it will free indio_dev through iio_device_unregister but

quite a bit later. While the work mentioned above will be used. The

sequence of operations that may lead to a UAF bug is as follows:

CPU0 CPU1

| at91_adc_workq_handler

at91_adc_remove |

iio_device_unregister(indio_dev) |

//free indio_dev a bit later |

| iio_push_to_buffers(indio_dev)

| //use indio_dev

Fix it by ensuring that the work is canceled before proceeding with

the cleanup in at91_adc_remove.

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2025-71199?

CVE-2025-71199 is a known-severity vulnerability. It was published on February 4, 2026.

How severe is CVE-2025-71199?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2025-71199?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2025-71199?

CyberStrike's AI-powered security agents can automatically detect CVE-2025-71199 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.