Impact
The Linux kernel’s io_uring query interface contains a flaw where the hdr.size field supplied by a caller is clamped for input but later reused for an output copy. Because hdr.size is a 32‑bit value, a crafted request can specify a size approaching four gigabytes, exceeding the actual data the kernel returns. When the kernel clears bytes beyond the intended buffer, user‑space memory is corrupted, which can cause the affected process to crash or become unstable. This vulnerability does not enable arbitrary code execution but can lead to a local denial of service by destroying application state or memory integrity.
Affected Systems
All Linux kernel installations that have not been upgraded to include the CVE‑2026‑81009 fix are affected. The issue resides in the core kernel, so every distribution that distributes a kernel built before the patch is at risk, regardless of the specific distribution version.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. The description indicates that a local user can invoke the IORING_REGISTER_QUERY ioctl without needing an existing io_uring ring, so the attack is locally exploitable. An adversary would need to craft an oversized hdr.size value, which could corrupt user memory or crash the target process, resulting in denial of service for that process or, if the vulnerability is triggered in a privileged component, potentially affecting the system’s stability.
OpenCVE Enrichment