Severity
Details
- CVSS score
- 5.5
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Overview
About vulnerability
In the Linux kernel, the following vulnerability has been resolved:
io_uring/futex: ensure io_futex_wait() cleans up properly on failure
The io_futex_data is allocated upfront and assigned to the io_kiocb async_data field, but the request isn’t marked with REQ_F_ASYNC_DATA at that point. Those two should always go together, as the flag tells io_uring whether the field is valid or not.
Additionally, on failure cleanup, the futex handler frees the data but does not clear ->async_data. Clear the data and the flag in the error path as well.
Thanks to Trend Micro Zero Day Initiative and particularly ReDress for reporting this.
Details
- Affected product:
- AlmaLinux 9.2 ESU , TuxCare 9.6 ESU
- Affected packages:
- kernel @ 5.14.0 (+1 more)
Fixes
KernelCare state
Live-patch status from KernelCare for each operating system.
| Operating system | Status | Covered kernels |
|---|---|---|
| AlmaLinux 10 | Released |
8 kernels
|
| AlmaLinux 9 | Released |
39 kernels
|
| Debian 13 | Will Not Fix | — |
| Oracle Linux 10 | Released |
8 kernels
|
| Oracle Linux 9 | Released |
39 kernels
|
| RHEL 10 | Released |
8 kernels
|
| RHEL 9 | Released |
39 kernels
|
| Rocky Linux 10 | Released |
5 kernels
|
| Rocky Linux 9 | Released |
30 kernels
|
| Ubuntu 24.04 | Released |
36 kernels
|