Vulnerability in the io_uring subsystem allows privilege escalation in the system

A vulnerability has been identified in the io_uring asynchronous I/O interface provided by the Linux kernel (CVE-2025-39698), allowing an unprivileged user to execute their code at the kernel level. This vulnerability is caused by a lack of object existence checks before performing operations on that object.

The vulnerability has been fixed in kernel updates 6.16.4 and 6.12.44. You can check the status of the new package version or the preparation of a patch in the distributions on the following pages (if the page is unavailable, developers of the distribution have not yet begun addressing the issue): Debian, Ubuntu, Fedora, SUSE/openSUSE, RHEL, Gentoo, and Arch.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster