SB2026012405 - Resource management error in Linux kernel io_uring
Published: January 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management error (CVE-ID: CVE-2025-71149)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the io_poll_remove() function in io_uring/poll.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0126560370ed5217958b85657b590ad25e8b9c00
- https://git.kernel.org/stable/c/13a8f7b88c2d40c6b33f6216190478dda95d385f
- https://git.kernel.org/stable/c/84230ad2d2afbf0c44c32967e525c0ad92e26b4e
- https://git.kernel.org/stable/c/8b777ab48441b153502772ecfc78c107d4353f29
- https://git.kernel.org/stable/c/c1669c03bfbc2a9b5ebff4428eecebe734c646fe