CVE-2026-45995 PUBLISHED

io_uring/zcrx: fix user_struct uaf

Assigner: Linux
Reserved: 13.05.2026 Published: 27.05.2026 Updated: 27.05.2026

In the Linux kernel, the following vulnerability has been resolved:

io_uring/zcrx: fix user_struct uaf

io_free_rbuf_ring() usees a struct user_struct, which io_zcrx_ifq_free() puts it down before destroying the ring.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 5c686456a4e83ef06c74d40be05c21a0ef136684 to 9feb88eeda6d288f93fcfb6bca563f89e316479d (excl.)
  • affected from 5c686456a4e83ef06c74d40be05c21a0ef136684 to 0fcccfd87152f957fa8312b841f6efef42a05a20 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.19 is affected
  • unaffected from 0 to 6.19 (excl.)
  • unaffected from 7.0.4 to 7.0.* (incl.)
  • unaffected from 7.1-rc1 to * (incl.)

References