Executive brief
A vulnerability was identified in the Linux kernel's io_uring subsystem, which is used for high-performance asynchronous input/output operations. A flaw in how the system manages user identity data during the cleanup of certain network interface queues could lead to a system crash or unpredictable behavior. This issue primarily affects system stability and could potentially be exploited by a local attacker to disrupt operations.
Technical details
A use-after-free (UAF) vulnerability exists in the io_uring/zcrx component of the Linux kernel. The root cause is an incorrect teardown sequence in io_zcrx_ifq_free(), where free_uid(ifq->user) is called before io_free_rbuf_ring(ifq). Because io_free_rbuf_ring() requires access to the user_struct, this results in a use-after-free condition. An attacker with local access could potentially exploit this race condition or improper cleanup sequence to cause a kernel panic or achieve local privilege escalation. The issue has been resolved by reordering the cleanup operations to ensure the user_struct is released only after the ring buffer is destroyed.
Affected products
- Linux Linux Kernel Versions including io_uring zcrx support
Timeline
- 2026-04-21: patched: Initial fix committed to mainline kernel
- 2026-05-27: disclosed: CVE published and NVD entry created