In the Linux kernel, the following vulnerability has been resolved:
iouring/waitid: always prune wait queue entry in iowaitid_wait()
For a successful return, always remove our entry from the wait queue entry list. Previously this was skipped if a cancelation was in progress, but this can race with another invocation of the wait queue entry callback.
[
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"209842399593572624780855770419342858816",
"276850456749999473231602940350144811519",
"137621479232701188604997865609172114882",
"48673805080141410922760996105676347826",
"298597186516496828693455625915929787197",
"144905188882918449954526644132235543119",
"199029787391381951118375320950435921820",
"277586332880868560963193013064507080738"
],
"threshold": 0.9
},
"target": {
"file": "io_uring/waitid.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@3e2205db2f0608898d535da1964e1b376aacfdaa",
"signature_version": "v1",
"id": "CVE-2025-40047-000f2e55"
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"209842399593572624780855770419342858816",
"276850456749999473231602940350144811519",
"137621479232701188604997865609172114882",
"48673805080141410922760996105676347826",
"298597186516496828693455625915929787197",
"144905188882918449954526644132235543119",
"199029787391381951118375320950435921820",
"277586332880868560963193013064507080738"
],
"threshold": 0.9
},
"target": {
"file": "io_uring/waitid.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2f8229d53d984c6a05b71ac9e9583d4354e3b91f",
"signature_version": "v1",
"id": "CVE-2025-40047-7d12b9ad"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 591.0,
"function_hash": "62368703475825415585195543822462130975"
},
"target": {
"file": "io_uring/waitid.c",
"function": "io_waitid_wait"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2f8229d53d984c6a05b71ac9e9583d4354e3b91f",
"signature_version": "v1",
"id": "CVE-2025-40047-7d4eaa6b"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 591.0,
"function_hash": "62368703475825415585195543822462130975"
},
"target": {
"file": "io_uring/waitid.c",
"function": "io_waitid_wait"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@3e2205db2f0608898d535da1964e1b376aacfdaa",
"signature_version": "v1",
"id": "CVE-2025-40047-bb086636"
}
]