Executive brief
A vulnerability was identified in the Linux kernel's io_uring subsystem, which handles high-performance data input and output. Under specific conditions involving the cancellation of background tasks, the system could mistakenly keep a reference to memory that has already been freed. This could lead to a system crash or allow an attacker to destabilize the operating system, potentially impacting the availability of services running on the affected machine.
Technical details
A use-after-free vulnerability exists in the Linux kernel's io-wq (io_uring worker queue) component. The function io_wq_remove_pending() fails to verify if a predecessor entry is hashed before updating the hash_tail array. When a hashed work item in bucket 0 is cancelled and preceded by a non-hashed work item, the system incorrectly stores a pointer to the non-hashed item in wq->hash_tail[0]. Because the fast path for non-hashed work does not clear this pointer, it becomes dangling once the associated io_kiocb is freed. Subsequent enqueues to the same hash bucket dereference this stale pointer, leading to memory corruption. The issue has been resolved by adding an explicit io_wq_is_hashed() check.
Affected products
- Linux Linux Kernel All versions prior to the June 2026 patches
Timeline
- 2026-05-11: other: Vulnerability fixed in source code by Nicholas Carlini
- 2026-06-08: disclosed: CVE published to NVD
References
- https://git.kernel.org/stable/c/252c5051dba9c709b6a72f2866f93e5e618b3f06
- https://git.kernel.org/stable/c/5a20ebf0c81b61f5ea3b1b529c100cad69b9f603
- https://git.kernel.org/stable/c/d376c131af7c7739a87ff037ed2fdb67c2542c8a
- https://git.kernel.org/stable/c/d6a2d7b04b5a093021a7a0e2e69e9d5237dfa8cc
- https://git.kernel.org/stable/c/d6bda9df0c0a3080804181464d5c0f4d78a4e769