CRITICAL 9.8 Microsoft

CVE-2025-71073

Input: lkkbd - disable pending work before freeing device

Microsoft Security Update 2026-Jan: Input: lkkbd - disable pending work before freeing device

Affected Products

References

Published: 2026-01-13 · Source: Microsoft · Feed updated: 2026-09-30
This critical severity vulnerability with a CVSS score of 9.8 was published on 2026-01-13 via Microsoft. Affected: azl3 kernel 6.6.119.3-3 on Azure Linux 3.0, azl3 kernel 6.6.126.1-1 on Azure Linux 3.0, cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0 and 5 more.

Risk Timeline

CVE Disclosed2026-01-13 · 259 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2025-62168 PoCSquid vulnerable to information disclosure via authentication credential leakageCRITICAL10.0
CVE-2026-44210Kata Containers have VM Escape via virtiofsd Argument Injection through Default-CRITICAL9.9
CVE-2026-15043DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= CRITICAL9.8
CVE-2026-17543SQL injection in ext-pgsql via E'...' backslash breakoutCRITICAL9.8
CVE-2026-38968ntopng through 6.6 is vulnerable to Predictable Session Identifier which can leaCRITICAL9.8
CVE-2026-53374drm/amdgpu: zero-initialize GART table on allocationCRITICAL9.8
vulnfeed aggregates 10239 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.