Home

Description

In the Linux kernel, the following vulnerability has been resolved: io_uring/zcrx: fix sgtable leak on mapping failures In an unlikely case when io_populate_area_dma() fails, which could only happen on a PAGE_POOL_32BIT_ARCH_WITH_64BIT_DMA machine, io_zcrx_map_area() will have an initialised and not freed table. It was supposed to be cleaned up in the error path, but !is_mapped prevents that.

PUBLISHED Reserved 2026-05-01 | Published 2026-05-06 | Updated 2026-05-06 | Assigner Linux

Product status

Default status
unaffected

439a98b972fbb1991819b5367f482cd4161ba39c (git) before f1ae403324311e143ef20e53cf9a5f01e312f7c9
affected

439a98b972fbb1991819b5367f482cd4161ba39c (git) before ef075c1464ac9047e2cf7d23cb020bfd0b8e4b60
affected

439a98b972fbb1991819b5367f482cd4161ba39c (git) before a983aae397767e9da931128ff2b5bf9066513ce3
affected

Default status
affected

6.18
affected

Any version before 6.18
unaffected

6.18.16 (semver)
unaffected

6.19.6 (semver)
unaffected

7.0 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/f1ae403324311e143ef20e53cf9a5f01e312f7c9

git.kernel.org/...c/ef075c1464ac9047e2cf7d23cb020bfd0b8e4b60

git.kernel.org/...c/a983aae397767e9da931128ff2b5bf9066513ce3

cve.org (CVE-2026-43224)

nvd.nist.gov (CVE-2026-43224)

Download JSON