In the Linux kernel, the following vulnerability has been resolved: io_uring: fix io_req_prep_async with provided buffers io_req_prep_async() can import provided buffers, commit the ring state by giving up on that before, it'll be reimported later if needed.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2025041827-CVE-2025-40364-d93c@gregkh/T