Home

Description

In the Linux kernel, the following vulnerability has been resolved: io_uring/zcrx: fix user_struct uaf io_free_rbuf_ring() usees a struct user_struct, which io_zcrx_ifq_free() puts it down before destroying the ring.

PUBLISHED Reserved 2026-05-13 | Published 2026-05-27 | Updated 2026-05-27 | Assigner Linux

Product status

Default status
unaffected

5c686456a4e83ef06c74d40be05c21a0ef136684 (git) before 9feb88eeda6d288f93fcfb6bca563f89e316479d
affected

5c686456a4e83ef06c74d40be05c21a0ef136684 (git) before 0fcccfd87152f957fa8312b841f6efef42a05a20
affected

Default status
affected

6.19
affected

Any version before 6.19
unaffected

7.0.4 (semver)
unaffected

7.1-rc1 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/9feb88eeda6d288f93fcfb6bca563f89e316479d

git.kernel.org/...c/0fcccfd87152f957fa8312b841f6efef42a05a20

cve.org (CVE-2026-45995)

nvd.nist.gov (CVE-2026-45995)

Download JSON