CVE-2025-71074 is a use-after-free vulnerability in the Linux kernel's functionfs component, specifically affecting how it handles the opening and removal of dynamic files. This race condition could lead to an attacker accessing freed memory, potentially causing system instability or arbitrary code execution. While no CVSS score is provided, its FAUCET Risk Score of 39/100 suggests a moderate severity. There is no evidence of active exploitation, and no public exploit code or Metasploit/Nuclei modules are available, though it has garnered significant community discussion with 10 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.6.35.1, < 6.19CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
2.6.35CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.35:-:*:*:*:*:*:* | ||
6.19CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.19:rc1:*:*:*:*:*:* | ||
6.19CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.19:rc2:*:*:*:*:*:* | ||
6.19CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.19:rc3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.