Junglewise Threat Intelligence

CVE-2026-43174: Linux Kernel io_uring improper resource management in zcrx

CVE-2026-43174 · Severity: medium · CVSS 5.5 · Published 2026-05-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's io_uring subsystem could allow a local user to cause a system crash. The issue occurs during the handling of high-performance network data transfers (zero-copy receive), where the system incorrectly manages memory resources when a connection queue is closed. This can lead to a denial-of-service condition, impacting the availability of the affected server.

Technical details

A vulnerability exists in the io_uring/zcrx component of the Linux kernel due to improper error handling during the closure of RX queues. Specifically, the code was releasing the zero-copy receive (zcrx) context directly instead of relying on proper reference counting, even though associated page pools might still be active. This race condition or premature release can lead to memory corruption or a kernel panic. The fix ensures that zcrx_unregister is used to allow reference counting to manage the lifecycle of the context. This is a local attack vector requiring low privileges to trigger a denial-of-service (DoS).

Affected products

  • Linux Linux Kernel 6.15 to 6.19.6

Timeline

  • 2026-05-06: disclosed
  • 2026-05-06: advisory
  • 2026-03-04: patched

References

Related threats