
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-71149 is a flaw in the Linux kernel's io_uring subsystem related to incorrect handling of the POLL_REMOVE opcode with updates. This CVE has been officially rejected/withdrawn by its CVE Numbering Authority (kernel.org) as of May 2, 2026, and is no longer considered a valid CVE entry. Prior to rejection, it was described as affecting Linux kernel versions 6.0 through 6.1.159, 6.2 through 6.6.119, 6.7 through 6.12.63, and 6.13 through 6.18.2, with a preliminary CVSS v3.1 score of 5.5 (Medium) (Red Hat Advisory, Feedly). The CVE was originally published on January 23, 2026, and subsequently rejected on May 2, 2026.
Before its rejection, the vulnerability was described as a logic error in the io_uring/poll subsystem (no formal CWE was assigned by NVD). The issue arose when POLL_REMOVE was used to update the events of a pending POLL_ADD request: if the update caused the POLL_ADD to trigger, the resulting completion was lost and no Completion Queue Entry (CQE) was posted to the application. A secondary issue caused the completion value to be incorrectly overwritten with -ECANCELED instead of retaining the value set by io_poll_add(). The root cause was an incomplete update to the io_uring core's completion handling logic when fixed return codes were introduced (Feedly).
The described impact was limited to local denial of service conditions. Low-privileged local attackers could trigger hangs or lost poll notifications in applications relying on io_uring poll operations, potentially causing those applications to stall or behave incorrectly. There was no confidentiality or integrity impact; the effect was confined to availability of the affected process or service (Feedly).
Because CVE-2025-71149 has been officially rejected by its CVE Numbering Authority, no remediation is required based on this identifier. Prior to rejection, patches had been committed to the Linux kernel stable trees targeting versions 6.1.160+, 6.6.120+, 6.12.64+, and 6.18.3+ (Feedly). Organizations should verify their vulnerability management tooling reflects the rejected status of this CVE to avoid unnecessary remediation effort. If scanner detections persist (e.g., Nessus, Qualys), consult the respective vendor for updated plugin definitions.
The CVE received routine automated coverage from vulnerability aggregators (Vulners, VulDB, CVEfeed.io) and scanner vendors (Tenable Nessus, Qualys) shortly after publication in January 2026. No notable researcher commentary or significant media coverage was identified. The CVE's rejection in May 2026 was a routine administrative action by kernel.org and did not generate significant public discussion.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."