Race condition in Linux kernel - CVE-2025-71303

 

Race condition in Linux kernel - CVE-2025-71303

Published: May 28, 2026


Vulnerability identifier: #VU132650
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-71303
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause unexpected behavior.

The vulnerability exists due to a race condition in the amdxdna power management logic when submitting commands during an autosuspend window. A local user can submit a command while a suspend or resume operation is in progress to cause unexpected behavior.

The issue occurs when the device has not actually resumed even though command submission proceeds.


Affected software

Linux kernel

How to mitigate CVE-2025-71303

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins