CVE-2025-39963: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: io_uring: fix incorrect io_kiocb reference in io_link_skb In io_link_skb function, there is a bug where prev_notif is incorrectly assigned using 'nd' instead of 'prev_nd'. This causes the context validation check to compare the current notification with itself instead of comparing it with the previous notification. Fix by using the correct prev_nd parameter when obtaining prev_notif.

Affected products

  • Linux Linux Kernel: from 6.10, before 6.12.49 (fixed in 6.12.49); from 6.13, before 6.16.9 (fixed in 6.16.9); version 6.17 only

Published 2025-10-09. Last modified 2026-07-30.