In the Linux kernel, the following vulnerability has been resolved: io_uring/futex: ensure io_futex_wait() cleans up properly on failure The io_futex_data is allocated upfront and assigned to the i…
高危 CVSS 7.8
摘要
In the Linux kernel, the following vulnerability has been resolved: io_uring/futex: ensure io_futex_wait() cleans up properly on failure The io_futex_data is allocated upfront and assigned to the io_kiocb async_data field, but the request isn't marked with REQ_F_ASYNC_DATA at that point. Those two should always go together, as the flag tells io_uring whether the field is valid or not. Additionally, on failure cleanup, the futex handler frees the data but does not clear ->async_data. Clear th…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://git.kernel.org/stable/c/508c1314b342b78591f51c4b5dadee31a88335df Patch
- https://git.kernel.org/stable/c/d34c04152df517c59979b4bf2a47f491e06d3256 Patch
- https://git.kernel.org/stable/c/d9f93172820a53ab42c4b0e5e65291f4f9d00ad2 Patch
- https://www.zerodayinitiative.com/advisories/ZDI-25-915/ Third Party Advisory
时间线
- nvd_ingest NVD