Impact
IO_uring’s waitid handling can ignore a cancellation flag when the work system falls back to a kworker. In that scenario, the callback runs with a different current task, causing __do_wait() to perform a child lookup relative to the kworker instead of the original submitting task. The result is that the wait may never be signaled or may return incorrect information, which can cause an application to block indefinitely or miss events. This flaw is governed by CWE‑663. The bug does not provide remote code execution or privilege escalation but can lead to an application‑level denial of service. Based on the description, the likely attack vector is local because the fault occurs during user‑initiated waitid requests.
Affected Systems
All Linux kernel images that include the io_uring waitid implementation and have not yet integrated the fix (commits 0879697520abda2383ed7be40572ad583b5c4b02, 14572de82e5022899e5856008bc9cac97004a88c, or 7bc98e2de8c58a2bfaf0f540eb096a386ecfc96c) are affected. The vulnerability applies to every kernel version that ships with this code path, regardless of distribution. Vendors should verify whether their kernel builds include the noted commit or a later one that resolves the issue.
Risk and Exploitability
The CVSS score of 7.8 highlights substantial risk, while an EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV, suggesting it has not been actively exploited. Exploitation requires local privileges to submit corrupted waitid requests, limiting the potential impact to denial of service within user processes rather than system compromise.
OpenCVE Enrichment