Junglewise Threat Intelligence

CVE-2026-46274: Linux Kernel use-after-free in io-wq remove_pending

CVE-2026-46274 · Severity: info · CVSS 0 · Published 2026-06-08

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's io_uring subsystem, which handles high-performance data input and output. Under specific conditions involving the cancellation of background tasks, the system could mistakenly keep a reference to memory that has already been freed. This could lead to a system crash or allow an attacker to destabilize the operating system, potentially impacting the availability of services running on the affected machine.

Technical details

A use-after-free vulnerability exists in the Linux kernel's io-wq (io_uring worker queue) component. The function io_wq_remove_pending() fails to verify if a predecessor entry is hashed before updating the hash_tail array. When a hashed work item in bucket 0 is cancelled and preceded by a non-hashed work item, the system incorrectly stores a pointer to the non-hashed item in wq->hash_tail[0]. Because the fast path for non-hashed work does not clear this pointer, it becomes dangling once the associated io_kiocb is freed. Subsequent enqueues to the same hash bucket dereference this stale pointer, leading to memory corruption. The issue has been resolved by adding an explicit io_wq_is_hashed() check.

Affected products

  • Linux Linux Kernel All versions prior to the June 2026 patches

Timeline

  • 2026-05-11: other: Vulnerability fixed in source code by Nicholas Carlini
  • 2026-06-08: disclosed: CVE published to NVD

References

Related threats