Junglewise Threat Intelligence

CVE-2025-38730: Linux Kernel io_uring memory corruption in network buffer retry

CVE-2025-38730 · Severity: high · CVSS 7.8 · Published 2025-09-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's high-performance I/O interface, io_uring, could allow local attackers to cause data corruption or potentially gain unauthorized access to information. The issue occurs when the system handles network data using shared memory buffers, failing to properly release them during certain retry operations. This could lead to multiple network connections accidentally using the same memory space, resulting in unpredictable application behavior or security breaches.

Technical details

A vulnerability exists in the Linux kernel io_uring/net subsystem where ring-provided buffers are improperly pinned across multiple execution contexts during partial retries. When MSG_WAITALL is set or streaming sockets process insufficient data, the kernel may fail to recycle or commit the buffer, leading to two primary risks: use-after-free scenarios if the buffer ring is unregistered before a retry, and memory aliasing if multiple sockets consume the same buffer group. This can result in an out-of-bounds write (CWE-787) or data corruption. The issue is resolved by ensuring partial retries commit provided buffers rather than pinning them. Patches are available for multiple stable kernel branches including 6.6.y, 6.12.y, 6.15.y, and 6.16.y.

Affected products

  • Linux Linux Kernel 6.4 to 6.6.102, 6.7 to 6.12.43, 6.13 to 6.15.10, 6.16 to 6.16.1

Timeline

  • 2025-08-12: other: Fix authored by Jens Axboe
  • 2025-08-20: patched: Fix committed to stable branches
  • 2025-09-04: disclosed: CVE published

References

Related threats