Junglewise Threat Intelligence

CVE-2026-64426: Linux Kernel memory leak in io_uring NOP operation

CVE-2026-64426 · Severity: info · CVSS 0 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A memory leak vulnerability was identified in the Linux kernel's io_uring subsystem, which handles high-performance asynchronous I/O operations. Under specific conditions involving 'NOP' operations and registered files, the system fails to properly release file references, leading to a gradual exhaustion of system memory. This could eventually result in a system crash or degraded performance, potentially allowing a local user to cause a denial-of-service condition.

Technical details

A resource leak exists in io_uring/nop.c due to inconsistent handling of the IOSQE_FIXED_FILE and IORING_NOP_FIXED_FILE flags. When a NOP request is submitted with IOSQE_FIXED_FILE set but IORING_NOP_FIXED_FILE absent, the kernel incorrectly acquires a normal file reference via io_file_get_normal(). Because the request is internally flagged as using a fixed file (REQ_F_FIXED_FILE), the completion handler io_put_file() skips the necessary reference decrement, causing a permanent leak of the file object. The fix involves synchronizing these flags during the request preparation phase to ensure consistent reference counting. Patches are available in stable kernel releases 6.18.39 and 7.1.4.

Affected products

  • Linux Linux Kernel 6.13 through 6.18.38, 7.1.3

Timeline

  • 2026-06-15: other: Initial patch authored
  • 2026-07-18: patched: Patch committed to stable trees
  • 2026-07-25: advisory: NVD advisory published

References

Related threats