PT-2026-4362 · Linux+2 · Linux Kernel+2
Published
2025-01-01
·
Updated
2026-05-11
·
CVE-2025-71149
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the Linux kernel’s io uring/poll subsystem where the handling of
io poll add() return values during updates is incorrect. Specifically, if a POLL ADD is pending and a POLL REMOVE is used to update the events, a completion can be lost if the update causes the POLL ADD to trigger. Additionally, the completion value may be incorrectly overwritten with -ECANCELED in certain update scenarios. The core of io uring was updated to handle completions consistently and with fixed return codes, which introduced this problem.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Ubuntu