Impact
In the Linux kernel, a logic flaw during bundle receive retries of io_uring caused the IORING_CQE_F_BUF_MORE flag to be incorrectly merged and retained across retries. This erroneous flag handling could lead userspace to advance the buffer ring head past an entry that the kernel was still using, potentially resulting in kernel memory corruption or a denial‑of‑service condition. The flaw therefore impacts the system.
Affected Systems
The vulnerability is present in the Linux Linux kernel; affected kernel versions are not enumerated in the available data, so any kernel revision prior to the fix may be impacted.
Risk and Exploitability
No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation. The CVSS score is not disclosed, so the exact severity cannot be quantified. Based on the description, the attack vector is local and requires an application that uses io_uring with buffer rings and bundle receive operations. Although no exploits have been reported, the potential for kernel memory corruption or a crash warrants prompt remediation.
OpenCVE Enrichment