CVE-2025-21756Linux kernel use-after-free in the vsock subsystem — fix auto-merged 11 hours before public disclosure, blocking the exploit chain on patched hosts.
Auto-merged fixes
A chronological record of the CVE fixes ZeroPatch auto-merged before public disclosure, from first detection through a landed patch.
CVE-2025-21756Linux kernel use-after-free in the vsock subsystem — fix auto-merged 11 hours before public disclosure, blocking the exploit chain on patched hosts.
CVE-2025-24201React Server Components deserialization flaw allowing boundary bypass — patch propagated to 14 downstream apps before the advisory went public.
CVE-2025-23114OpenSSL XLLO handshake state-machine defect — zeroPatch PR accepted upstream and rolled into 6 vendor LTS branches during the embargo window.
CVE-2025-22869Next.js middleware token-validation regression — surface patched across staging ahead of disclosure, no customer interrupt.
CVE-2025-22091curl URL parser parser-confusion bug on percent-encoded NUL bytes —tracked fix merged into our deployment pin the same day.