PT-2025-41377 · Linux+1 · Linux Kernel+1

Published

2025-09-19

·

Updated

2026-03-13

·

CVE-2025-39963

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the Linux kernel’s io uring functionality within the io link skb function. A bug causes an incorrect assignment of prev notif using nd instead of prev nd during context validation. This results in the current notification being compared with itself instead of the previous notification. The issue is addressed by using the correct prev nd parameter when obtaining prev notif.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Leak

Weakness Enumeration

Related Identifiers

BDU:2026-02406
CVE-2025-39963
OPENSUSE-SU-2025:20091-1
SUSE-SU-2025:21080-1
SUSE-SU-2025:21147-1
SUSE-SU-2025:21180-1
SUSE-SU-2026:20149-1
SUSE-SU-2026:20164-1
SUSE-SU-2026:20168-1
SUSE-SU-2026:20169-1
SUSE-SU-2026:20171-1
SUSE-SU-2026:20202-1

Affected Products

Linux Kernel
Suse