cbcvebase.
CVE-2025-71239
published 2026-03-17

CVE-2025-71239: In the Linux kernel, the following vulnerability has been resolved: audit: add fchmodat2() to change attributes class fchmodat2(), introduced in version 6.6 is…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.5th percentile
In the Linux kernel, the following vulnerability has been resolved: audit: add fchmodat2() to change attributes class fchmodat2(), introduced in version 6.6 is currently not in the change attribute class of audit. Calling fchmodat2() to change a file attribute in the same fashion than chmod() or fchmodat() will bypass audit rules such as: -w /tmp/test -p rwa -k test_rwa The current patch adds fchmodat2() to the change attributes class.

Affected

59 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.6-1 (forky)linux 6.19.6-1 (forky)
linuxlinux
linuxlinux>= 09da082b07bbae1c11d9560c8502800039aebcea < 91e27bc79c3bca93c06bf5a471d47df9a35b374191e27bc79c3bca93c06bf5a471d47df9a35b3741
linuxlinux>= 09da082b07bbae1c11d9560c8502800039aebcea < 3e762a03713e8c25ca0108c075d662c897fc06233e762a03713e8c25ca0108c075d662c897fc0623
linuxlinux>= 09da082b07bbae1c11d9560c8502800039aebcea < 4fed776ca86378da7dd743a7b648e20b025ba8ef4fed776ca86378da7dd743a7b648e20b025ba8ef
linuxlinux>= 09da082b07bbae1c11d9560c8502800039aebcea < c4334c0d0e7d6f02ed93756fd4ba807e3d00c05fc4334c0d0e7d6f02ed93756fd4ba807e3d00c05f
linuxlinux>= 09da082b07bbae1c11d9560c8502800039aebcea < 4f493a6079b588cf1f04ce5ed6cdad45ab0d53dc4f493a6079b588cf1f04ce5ed6cdad45ab0d53dc
linuxlinux_kernel>= 0 < 6.19.6-16.19.6-1
linuxlinux_kernel>= 6.13 < 6.18.166.18.16
linuxlinux_kernel>= 6.13.0 < 6.18.166.18.16
linuxlinux_kernel>= 6.19 < 6.19.66.19.6
linuxlinux_kernel>= 6.19.0 < 6.19.66.19.6
linuxlinux_kernel>= 6.6 < 6.6.1286.6.128
linuxlinux_kernel>= 6.6.0 < 6.6.1286.6.128
linuxlinux_kernel>= 6.7 < 6.12.756.12.75
linuxlinux_kernel>= 6.7.0 < 6.12.756.12.75
msrcazl3_kernel_6.6.126.1-1_on_azure_linux_3.0
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15
ubuntulinux-aws-6.8
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-5.15
ubuntulinux-azure-6.8

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_ubuntu8.8HIGH
vendor_msrc5.5MEDIUM
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.