CVE-2026-64425 PUBLISHED

io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item

Assigner: Linux
Reserved: 19.07.2026 Published: 25.07.2026 Updated: 25.07.2026

In the Linux kernel, the following vulnerability has been resolved:

io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item

commit 10dc95939817 ("io_uring/io-wq: check IO_WQ_BIT_EXIT inside work run loop") fixed the obvious case where io_worker_handle_work() took one exit-bit snapshot before draining pending work, but the fix stops one level too early.

io_worker_handle_work() now re-checks IO_WQ_BIT_EXIT in its outer work run loop, yet it still snapshots that bit once before processing a whole dependent linked-work chain. If io_wq_exit_start() sets IO_WQ_BIT_EXIT after the first linked item has started, the remaining linked items can still reuse stale do_kill = false, skip IO_WQ_WORK_CANCEL, and continue running after exit has begun.

Move the check further inside, so it covers linked items too. Note: this is a syzbot special as it loves setting up tons of slow linked work on weird devices like msr that take forever to read, and immediately close the ring. Exit then takes a long time.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 065dd936195a3466b8ebe5f9287400987ee3c063 to 14b7ecad2ec56699325180a744f4b19f046401bb (excl.)
  • affected from 27e47500fac23d15b7dc93ff650bc4844d2581bd to d179533c610e1b4c6aa436e3c1fd1b719d2c727c (excl.)
  • affected from d05d99573f81a091547b1778b9a50120f5d6c68a to 6e2f51f3e06773c2ee98ad09738f0908b48f76f9 (excl.)
  • affected from 85eb83694a91c89d9abe615d717c0053c3efa714 to ea61b04e1d7242cb37f5ed2cc91cf21a493f6597 (excl.)
  • affected from 2e8ca1078b14142db2ce51cbd18ff9971560046b to b6f179a653a934736c88d820fe0098c3c2532549 (excl.)
  • affected from bdf0bf73006ea8af9327cdb85cfdff4c23a5f966 to 1636d85dc139b07c0449308f2bb5e0c7a2e0da99 (excl.)
  • affected from 10dc959398175736e495f71c771f8641e1ca1907 to ab85765cbe3258b43dc6729af0e6ce3a87a133d8 (excl.)
  • affected from 10dc959398175736e495f71c771f8641e1ca1907 to 29bef9934b2521f787bb15dd1985d4c0d12ae02a (excl.)
  • affected from 5.10.253 to 5.10.261 (excl.)
  • affected from 5.15.203 to 5.15.212 (excl.)
  • affected from 6.1.167 to 6.1.178 (excl.)
  • affected from 6.6.122 to 6.6.145 (excl.)
  • affected from 6.12.68 to 6.12.96 (excl.)
  • affected from 6.18.8 to 6.18.39 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.19 is affected
  • unaffected from 0 to 6.19 (excl.)
  • unaffected from 5.10.261 to 5.10.* (incl.)
  • unaffected from 5.15.212 to 5.15.* (incl.)
  • unaffected from 6.1.178 to 6.1.* (incl.)
  • unaffected from 6.6.145 to 6.6.* (incl.)
  • unaffected from 6.12.96 to 6.12.* (incl.)
  • unaffected from 6.18.39 to 6.18.* (incl.)
  • unaffected from 7.1.4 to 7.1.* (incl.)
  • unaffected from 7.2-rc1 to * (incl.)

References