Junglewise Threat Intelligence

CVE-2026-45995: Linux Kernel use-after-free in io_uring zcrx cleanup

CVE-2026-45995 · Severity: info · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's io_uring subsystem, which is used for high-performance asynchronous input/output operations. A flaw in how the system manages user identity data during the cleanup of certain network interface queues could lead to a system crash or unpredictable behavior. This issue primarily affects system stability and could potentially be exploited by a local attacker to disrupt operations.

Technical details

A use-after-free (UAF) vulnerability exists in the io_uring/zcrx component of the Linux kernel. The root cause is an incorrect teardown sequence in io_zcrx_ifq_free(), where free_uid(ifq->user) is called before io_free_rbuf_ring(ifq). Because io_free_rbuf_ring() requires access to the user_struct, this results in a use-after-free condition. An attacker with local access could potentially exploit this race condition or improper cleanup sequence to cause a kernel panic or achieve local privilege escalation. The issue has been resolved by reordering the cleanup operations to ensure the user_struct is released only after the ring buffer is destroyed.

Affected products

  • Linux Linux Kernel Versions including io_uring zcrx support

Timeline

  • 2026-04-21: patched: Initial fix committed to mainline kernel
  • 2026-05-27: disclosed: CVE published and NVD entry created

References

Related threats