Executive brief
A vulnerability in the Linux kernel's io_uring subsystem could allow a local user to cause a system crash or potentially access sensitive kernel memory. The issue occurs when the system processes specific high-performance I/O requests, where it fails to properly check the boundaries of memory buffers. This could lead to a denial of service or unauthorized information disclosure on affected Linux systems.
Technical details
An out-of-bounds read vulnerability exists in the Linux kernel io_uring subsystem when IORING_SETUP_SQE_MIXED is used without IORING_SETUP_NO_SQARRAY. The root cause is that io_init_req() validates the logical Submission Queue (SQ) head position instead of the physical SQE index. An unprivileged local user can manipulate the sq_array to map a logical position to the last physical SQE slot. This causes a subsequent 128-byte memcpy in io_uring_cmd_sqe_copy() to read 64 bytes beyond the end of the SQE array. The vulnerability has been patched by replacing the logical head check with direct validation of the physical SQE index.
Affected products
- Linux Linux Kernel 6.19 to 6.19.9
Timeline
- 2026-03-11: patched: Fix committed to mainline kernel
- 2026-05-08: disclosed: CVE published