We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2022-49791

io_uring: fix multishot accept request leaks



Description

In the Linux kernel, the following vulnerability has been resolved: io_uring: fix multishot accept request leaks Having REQ_F_POLLED set doesn't guarantee that the request is executed as a multishot from the polling path. Fortunately for us, if the code thinks it's multishot issue when it's not, it can only ask to skip completion so leaking the request. Use issue_flags to mark multipoll issues.

Reserved 2025-05-01 | Published 2025-05-01 | Updated 2025-05-04 | Assigner Linux

Product status

Default status
unaffected

390ed29b5e425ba00da2b6113b74a14949f71b02 before 0e4626de856ef8f25ecd9c716e76d4f95ce95639
affected

390ed29b5e425ba00da2b6113b74a14949f71b02 before 91482864768a874c4290ef93b84a78f4f1dac51b
affected

Default status
affected

5.19
affected

Any version before 5.19
unaffected

6.0.10
unaffected

6.1
unaffected

References

git.kernel.org/...c/0e4626de856ef8f25ecd9c716e76d4f95ce95639

git.kernel.org/...c/91482864768a874c4290ef93b84a78f4f1dac51b

cve.org (CVE-2022-49791)

nvd.nist.gov (CVE-2022-49791)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2022-49791

Support options

Helpdesk Chat, Email, Knowledgebase