Junglewise Threat Intelligence

CVE-2026-23263: Linux Kernel memory leak in io_uring zcrx

CVE-2026-23263 · Severity: info · CVSS 5.5 · Published 2026-03-18

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A memory leak vulnerability was identified in the Linux kernel's io_uring subsystem, specifically within the zero-copy receive (zcrx) feature. This component is used to improve network performance by reducing data copying between the kernel and applications. An exploit could allow a local user to exhaust system memory, potentially leading to a system crash or denial of service.

Technical details

A memory leak (CWE-401) exists in the io_uring/zcrx component of the Linux kernel. The vulnerability occurs in the io_import_umem function when an sg_alloc_table_from_pages_pfn call fails. While a previous fix addressed the leakage of individual pages, it failed to release the memory allocated for the page array itself. A local attacker with sufficient privileges to utilize io_uring zcrx features could trigger this failure path repeatedly to exhaust kernel memory (kvmalloc). The issue has been resolved by adding a kvfree(pages) call in the error path.

Affected products

  • Linux Linux Kernel 6.17 to 6.18.10, 6.19-rc1 to 6.19-rc8

Timeline

  • 2026-02-01: other: Patch authored
  • 2026-03-18: disclosed: CVE published
  • 2026-05-22: advisory: NVD analysis completed

References

Related threats