CVE-2025-40047 is a use-after-free vulnerability in the Linux kernel's io_uring IORING_OP_WAITID operation. A low-privileged local attacker can race cancellation handling in io_waitid_wait() because a wait-queue entry may not be pruned after a successful return, permitting repeated callbacks, list corruption, a system crash, or potential privilege escalation. The flaw was introduced in Linux kernel 6.7.
The issue is fixed in Linux kernel versions 6.12.53, 6.17.3, and 6.18-rc1; maintainers recommend upgrading to a current stable release rather than cherry-picking the patch. Red Hat rated the vulnerability 7.8 under CVSS v3.1 and released fixes for supported Red Hat Enterprise Linux 9 and 10 kernel streams, while the RHEL 9 kernel-rt stream remains affected.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2025:22854, providing fixed RHEL 10 kernel packages for CVE-2025-40047.
Red Hat released RHSA-2025:21933, providing fixed RHEL 9.6 Extended Update Support kernel packages for CVE-2025-40047.
Red Hat released RHSA-2025:21469, providing fixed RHEL 9 kernel packages for CVE-2025-40047.
Red Hat released RHSA-2026:1727, providing fixed RHEL 10.0 Extended Update Support kernel packages for CVE-2025-40047.
The Linux kernel CVE team assigned CVE-2025-40047 for an io_uring waitid flaw in io_uring/waitid.c, where a cancellation race can leave a wait-queue entry installed and permit competing callbacks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.