Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-71073

28
FAUCET Score

CVE-2025-71073 describes a use-after-free vulnerability in the Linux kernel's lkkbd input driver. This flaw occurs when the lkkbd structure is freed before pending reinitialization work is properly canceled, allowing the work handler to access freed memory. While a CVSS score is not available, the potential for a use-after-free suggests a local attack vector with possible denial-of-service or privilege escalation implications. There is no public exploit code, Metasploit module, or evidence of active exploitation, although it has garnered significant community discussion and a security update from openSUSE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.12.1, < 6.12.64CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.13, < 6.18.3CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
2.6.12CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:2.6.12:-:*:*:*:*:*:*
2.6.12CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:*
2.6.12CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.12%
Probability of exploitation in next 30 days
EPSS Percentile
2.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0012 is in the 11th percentile among its peer group of 17,061 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (13)

ubuntupatch availablevia ubuntu_usn
Product: linux-raspi (questing)Fixed in: 6.17.0-1014.14
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-6.17 (noble)Fixed in: 6.17.0-1013.13~24.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-oem-6.17 (noble)Fixed in: 6.17.0-1020.20
ubuntupatch availablevia ubuntu_usn
Product: linux-azure (questing)Fixed in: 6.17.0-1013.13
ubuntupatch availablevia ubuntu_usn
Product: linux (questing)Fixed in: 6.17.0-22.22
ubuntupatch availablevia ubuntu_usn
Product: linux-realtime (questing)Fixed in: 6.17.0-1010.11
ubuntupatch availablevia ubuntu_usn
Product: linux-gcp-6.17 (noble)Fixed in: 6.17.0-1012.12~24.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-gcp (questing)Fixed in: 6.17.0-1012.12
ubuntupatch availablevia ubuntu_usn
Product: linux-aws-6.17 (noble)Fixed in: 6.17.0-1012.12~24.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-hwe-6.17 (noble)Fixed in: 6.17.0-22.22~24.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-oracle-6.17 (noble)Fixed in: 6.17.0-1011.11~24.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-aws (questing)Fixed in: 6.17.0-1012.12
ubuntupatch availablevia ubuntu_usn
Product: linux-oracle (questing)Fixed in: 6.17.0-1011.11

Vendor Advisories (7)

ubuntuUSN-8257-1

Linux kernel (Raspberry Pi) vulnerabilities

May 7, 2026
ubuntuUSN-8245-1

Linux kernel vulnerabilities

May 7, 2026
ubuntuUSN-8183-2

Linux kernel vulnerabilities

Apr 23, 2026
ubuntuUSN-8183-1

Linux kernel (GCP) vulnerabilities

Apr 17, 2026
ubuntuUSN-8177-1

Linux kernel vulnerabilities

Apr 16, 2026
microsoft2026-Jan/CVE-2025-71073Critical

Input: lkkbd - disable pending work before freeing device

Jan 13, 2026
redhatCVE-2025-71073

kernel: Input: lkkbd - disable pending work before freeing device

Jan 13, 2026

References

git.kernel.org / stable/c/3a7cd1397c209076c371d53bf39a55c138f62342
Patch
git.kernel.org / stable/c/cffc4e29b1e2d44ab094cf142d7c461ff09b9104
Patch
git.kernel.org / stable/c/e58c88f0cb2d8ed89de78f6f17409d29cfab6c5c
Patch