Executive brief
A vulnerability exists in the Linux kernel's io_uring subsystem, which is used for high-performance data input and output. Under specific conditions, particularly when running with administrative (root) privileges, the system may incorrectly calculate memory requirements for large data regions. This could lead to system instability or allow an attacker to compromise the integrity of the operating system.
Technical details
An integer overflow vulnerability exists in io_uring/memmap.c within the io_region_allocate_pages function. The root cause is a missing type cast of the 'nr_pages' variable to 'size_t' before performing a bitwise shift (PAGE_SHIFT), which can result in an overflow if the resulting size exceeds UINT_MAX (4GB). While standard users are typically restricted by locked_vm limits, root users bypass these accounting checks, making it possible to trigger the overflow. An attacker with local access and sufficient privileges could exploit this to cause memory corruption. Patches have been released for various stable kernel branches including 6.15.11 and 6.16.2.
Affected products
- Linux Linux Kernel 6.14 to 6.15.11, 6.16 to 6.16.2
Timeline
- 2025-08-08: patched: Initial fix committed by Jens Axboe
- 2025-09-12: disclosed: CVE-2025-39793 published