Junglewise Threat Intelligence

CVE-2026-81009: Linux kernel io_uring query buffer overread in copy_struct_to_user

CVE-2026-81009 · Severity: info · CVSS 5.3 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's io_uring subsystem contains a flaw in its query interface that allows a malicious application to request excessive memory clearing operations. An attacker can specify a query size up to 4 GiB, causing the kernel to zero memory beyond intended bounds, potentially exposing sensitive kernel data or causing system instability. This interface is reachable without requiring an active io_uring ring.

Technical details

The vulnerability exists in io_handle_query_entry() within the io_uring query path. The function clamps hdr.size for inbound copy_from_user() operations but retains the original user-supplied value in the usize variable. This unclamped usize is then passed to copy_struct_to_user(), which clears trailing bytes when usize exceeds the kernel result size. Since hdr.size is a __u32, an attacker can request up to ~4 GiB of zeroing, including on error paths where res_size is 0. The interface is reachable via IORING_REGISTER_QUERY without requiring a ring context. The fix caps the maximum size to PAGE_SIZE, aligning with recommended practices for copy_struct_* interfaces.

Affected products

  • Linux Linux Kernel 6.18 and later

Timeline

  • 2026-09-11: disclosed: CVE-2026-81009 published

References

Related threats