In the Linux kernel, the following vulnerability has been resolved:
io_uring/waitid: clear waitid info before copying it to userspace
IORING_OP_WAITID stores its result fields in struct io_waitid::info and
later copies them to userspace siginfo. The prep path initializes the
request arguments, but it does not initialize info itself.
If the wait operation completes without reporting a child event, the common
wait code can return without writing wo_info. In that case io_waitid_finish()
still copies iw->info to userspace, exposing stale bytes from the reused
io_kiocb command storage.
Clear the result storage during prep so the io_uring path matches the
regular waitid syscall, which uses a zero-initialized struct waitid_info.
References
Configurations
Configuration 1 (hide)
|
History
23 Jul 2026, 08:10
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
08 Jul 2026, 14:50
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://git.kernel.org/stable/c/4d2a0de611ab60d02fc768ae0cd5918b16bd5474 - Patch | |
| References | () https://git.kernel.org/stable/c/93d93f5f8da791e98159795c6ef683f45bd95d13 - Patch | |
| References | () https://git.kernel.org/stable/c/954518e5a4a5efc5033253f6e36fc7b9f98363a3 - Patch | |
| References | () https://git.kernel.org/stable/c/b737c6612c60c23b40a9f31749b99e6f61943847 - Patch | |
| First Time |
Linux linux Kernel
Linux |
|
| CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
| CWE | NVD-CWE-noinfo |
09 Jun 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-09 09:16
Updated : 2026-07-23 08:10
NVD link : CVE-2026-46315
Mitre link : CVE-2026-46315
CVE.ORG link : CVE-2026-46315
JSON object : View
Products Affected
linux
- linux_kernel
CWE
