cbcvebase.
CVE-2025-71203
published 2026-02-14

CVE-2025-71203: In the Linux kernel, the following vulnerability has been resolved: riscv: Sanitize syscall table indexing under speculation The syscall number is a…

PriorityP431high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.13%
2.7th percentile
In the Linux kernel, the following vulnerability has been resolved: riscv: Sanitize syscall table indexing under speculation The syscall number is a user-controlled value used to index into the syscall table. Use array_index_nospec() to clamp this value after the bounds check to prevent speculative out-of-bounds access and subsequent data leakage via cache side channels.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.18.10-1 (forky)linux 6.18.10-1 (forky)
linuxlinux
linuxlinux>= f0bddf50586da81360627a772be0e355b62f071e < 33743ec6679aa364ee19d1afbaa50593e9e6e44333743ec6679aa364ee19d1afbaa50593e9e6e443
linuxlinux>= f0bddf50586da81360627a772be0e355b62f071e < c45848936ebdb4fcab92f8c39510db83c16d0239c45848936ebdb4fcab92f8c39510db83c16d0239
linuxlinux>= f0bddf50586da81360627a772be0e355b62f071e < 8b44e753795107a22ba31495686e83f4aca48f368b44e753795107a22ba31495686e83f4aca48f36
linuxlinux>= f0bddf50586da81360627a772be0e355b62f071e < 25fd7ee7bf58ac3ec7be3c9f82ceff153451946c25fd7ee7bf58ac3ec7be3c9f82ceff153451946c
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.73-16.12.73-1
linuxlinux_kernel>= 0 < 6.18.10-16.18.10-1
linuxlinux_kernel>= 6.13 < 6.18.106.18.10
linuxlinux_kernel>= 6.4 < 6.12.706.12.70
ubuntulinux
ubuntulinux-aws
ubuntulinux-azure
ubuntulinux-azure-6.8
ubuntulinux-azure-fde
ubuntulinux-azure-fde-6.8
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp
ubuntulinux-gcp-6.8
ubuntulinux-gcp-fips
ubuntulinux-gke
ubuntulinux-gkeop
ubuntulinux-hwe-6.8

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.0HIGH
vendor_debian7.0LOW
vendor_redhat7.0HIGH
vendor_ubuntu2.0LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.