Description
In the Linux kernel, the following vulnerability has been resolved:

io_uring/query: cap user size passed to copy_struct_to_user

io_handle_query_entry() clamps hdr.size for the inbound copy_from_user()
but keeps the original user value as usize. copy_struct_to_user() uses
that usize and, when it is larger than the kernel result, clear_user()s
the trailing bytes.

As hdr.size is a __u32, a query can request nearly 4 GiB of zeroing,
including on the error path where res_size stays 0. The interface is
reachable without a ring via IORING_REGISTER_QUERY.

Reject sizes larger than PAGE_SIZE, as recommended for copy_struct_*
interfaces.
Published: 2026-09-11
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Denial of Service
Action: Patch Kernel
AI Analysis

Impact

The Linux kernel’s io_uring query interface contains a flaw where the hdr.size field supplied by a caller is clamped for input but later reused for an output copy. Because hdr.size is a 32‑bit value, a crafted request can specify a size approaching four gigabytes, exceeding the actual data the kernel returns. When the kernel clears bytes beyond the intended buffer, user‑space memory is corrupted, which can cause the affected process to crash or become unstable. This vulnerability does not enable arbitrary code execution but can lead to a local denial of service by destroying application state or memory integrity.

Affected Systems

All Linux kernel installations that have not been upgraded to include the CVE‑2026‑81009 fix are affected. The issue resides in the core kernel, so every distribution that distributes a kernel built before the patch is at risk, regardless of the specific distribution version.

Risk and Exploitability

The CVSS score of 4.7 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. The description indicates that a local user can invoke the IORING_REGISTER_QUERY ioctl without needing an existing io_uring ring, so the attack is locally exploitable. An adversary would need to craft an oversized hdr.size value, which could corrupt user memory or crash the target process, resulting in denial of service for that process or, if the vulnerability is triggered in a privileged component, potentially affecting the system’s stability.

Generated by OpenCVE AI on September 21, 2026 at 02:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel release that contains the CVE‑2026‑81009 patch.
  • If an immediate kernel upgrade is unavailable, reconfigure the kernel to disable the IORING_REGISTER_QUERY ioctl or compile the kernel with the io_uring interface disabled, and apply a system‑wide policy (e.g., SELinux or AppArmor) that limits the ioctl to trusted users only.
  • After updating the kernel or applying the configuration change, reboot the system or restart affected services to ensure the new kernel and policies are active.

Generated by OpenCVE AI on September 21, 2026 at 02:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: io_uring/query: cap user size passed to copy_struct_to_user io_handle_query_entry() clamps hdr.size for the inbound copy_from_user() but keeps the original user value as usize. copy_struct_to_user() uses that usize and, when it is larger than the kernel result, clear_user()s the trailing bytes. As hdr.size is a __u32, a query can request nearly 4 GiB of zeroing, including on the error path where res_size stays 0. The interface is reachable without a ring via IORING_REGISTER_QUERY. Reject sizes larger than PAGE_SIZE, as recommended for copy_struct_* interfaces.
Title io_uring/query: cap user size passed to copy_struct_to_user
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:43:00.074Z

Reserved: 2026-08-26T14:34:25.812Z

Link: CVE-2026-81009

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:09.687

Modified: 2026-09-11T20:19:09.687

Link: CVE-2026-81009

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:00Z

Links: CVE-2026-81009 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T02:30:08Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling