Executive brief
A vulnerability was found in the Linux kernel's io_uring subsystem, which is used for high-performance input/output operations. An error in how the system handles zero-length data buffers allows a local attacker to trigger an out-of-bounds memory read. This could lead to the exposure of sensitive kernel information or cause a system crash, potentially disrupting operations.
Technical details
An out-of-bounds read vulnerability exists in the Linux kernel's io_uring/rsrc component. The function validate_fixed_range() incorrectly allows a buffer address at the exact end of a registered region when the length is zero due to a strict greater-than check. This causes io_import_fixed() to compute an offset equal to the buffer length, leading the bvec skip logic to read from out-of-bounds slab memory. A local attacker can exploit this to read kernel memory or cause a denial of service (kernel panic). The issue has been resolved by adding an early return in io_import_fixed() for zero-length imports.
Affected products
- Linux Linux Kernel 6.15 to 6.18.22, 6.19 to 6.19.12, 7.0-rc1 to 7.0-rc6
Timeline
- 2026-03-30: other: Patch authored
- 2026-05-01: disclosed
- 2026-05-01: advisory