Executive brief
The Linux kernel's io_uring subsystem contains a flaw in its query interface that allows a malicious application to request excessive memory clearing operations. An attacker can specify a query size up to 4 GiB, causing the kernel to zero memory beyond intended bounds, potentially exposing sensitive kernel data or causing system instability. This interface is reachable without requiring an active io_uring ring.
Technical details
The vulnerability exists in io_handle_query_entry() within the io_uring query path. The function clamps hdr.size for inbound copy_from_user() operations but retains the original user-supplied value in the usize variable. This unclamped usize is then passed to copy_struct_to_user(), which clears trailing bytes when usize exceeds the kernel result size. Since hdr.size is a __u32, an attacker can request up to ~4 GiB of zeroing, including on error paths where res_size is 0. The interface is reachable via IORING_REGISTER_QUERY without requiring a ring context. The fix caps the maximum size to PAGE_SIZE, aligning with recommended practices for copy_struct_* interfaces.
Affected products
- Linux Linux Kernel 6.18 and later
Timeline
- 2026-09-11: disclosed: CVE-2026-81009 published