CVE-2025-71149: io_uring/poll: correctly handle io_poll_add() return value on update
Published Jan 23, 2026
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
5 affected components
Linux Linux kernel
Linux Linux kernel>=6.0<6.1.160
Linux Linux kernel>=6.2<6.6.120
Linux Linux kernel>=6.7<6.12.64
Linux Linux kernel>=6.13<6.18.3
Remediation
Event History
Jan 23, 2026
CVE Published
via MITRE·02:15 PM
Rejected
via MITRE·02:15 PM
Data Sourced
via NVD·03:16 PM
Description
May 2, 2026
Rejected
via MITRE·06:18 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-71149?
CVE-2025-71149 has been classified as a medium-severity vulnerability in the Linux kernel.
2
How do I fix CVE-2025-71149?
To fix CVE-2025-71149, you should upgrade to the latest version of the Linux kernel that includes the patch for this vulnerability.
3
What software is affected by CVE-2025-71149?
CVE-2025-71149 affects the Linux kernel, specifically versions prior to the patch being applied.
4
What is the nature of the vulnerability CVE-2025-71149?
CVE-2025-71149 involves incorrect handling of the return value in the io_poll_add() function when updating the io_uring subsystem.
5
Can CVE-2025-71149 lead to denial of service?
Yes, CVE-2025-71149 could potentially lead to denial of service conditions in systems utilizing the io_uring feature.