CVE-2026-46315

In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: clear waitid info before copying it to userspace IORING_OP_WAITID stores its result fields in struct io_waitid::info and later copies them to userspace siginfo. The prep path initializes the request arguments, but it does not initialize info itself. If the wait operation completes without reporting a child event, the common wait code can return without writing wo_info. In that case io_waitid_finish() still copies iw->info to userspace, exposing stale bytes from the reused io_kiocb command storage. Clear the result storage during prep so the io_uring path matches the regular waitid syscall, which uses a zero-initialized struct waitid_info.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*

History

23 Jul 2026, 08:10

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: io_uring/waitid: limpiar la información de waitid antes de copiarla al espacio de usuario IORING_OP_WAITID almacena sus campos de resultado en la estructura io_waitid::info y luego los copia a siginfo del espacio de usuario. La ruta de preparación inicializa los argumentos de la solicitud, pero no inicializa la propia información. Si la operación de espera se completa sin informar un evento hijo, el código de espera común puede regresar sin escribir wo_info. En ese caso, io_waitid_finish() todavía copia iw->info al espacio de usuario, exponiendo bytes obsoletos del almacenamiento de comandos io_kiocb reutilizado. Limpiar el almacenamiento de resultados durante la preparación para que la ruta de io_uring coincida con la llamada al sistema waitid regular, que utiliza una estructura waitid_info inicializada a cero.

08 Jul 2026, 14:50

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/4d2a0de611ab60d02fc768ae0cd5918b16bd5474 - () https://git.kernel.org/stable/c/4d2a0de611ab60d02fc768ae0cd5918b16bd5474 - Patch
References () https://git.kernel.org/stable/c/93d93f5f8da791e98159795c6ef683f45bd95d13 - () https://git.kernel.org/stable/c/93d93f5f8da791e98159795c6ef683f45bd95d13 - Patch
References () https://git.kernel.org/stable/c/954518e5a4a5efc5033253f6e36fc7b9f98363a3 - () https://git.kernel.org/stable/c/954518e5a4a5efc5033253f6e36fc7b9f98363a3 - Patch
References () https://git.kernel.org/stable/c/b737c6612c60c23b40a9f31749b99e6f61943847 - () https://git.kernel.org/stable/c/b737c6612c60c23b40a9f31749b99e6f61943847 - Patch
First Time Linux linux Kernel
Linux
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE NVD-CWE-noinfo

09 Jun 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-09 09:16

Updated : 2026-07-23 08:10


NVD link : CVE-2026-46315

Mitre link : CVE-2026-46315

CVE.ORG link : CVE-2026-46315


JSON object : View

Products Affected

linux

  • linux_kernel