Linux Kernel io_uring Notification Context Vulnerability

Vulnerability

A vulnerability in the Linux kernel's io_uring implementation has been addressed. The issue involved improper handling of chained notification contexts, which could lead to ambiguous reports and assumptions about notification completion. The vulnerability has been resolved by ensuring that zero-copy (zc) operations only link buffer information for requests originating from the same context.

Impact

Exploitation of this vulnerability could lead to incorrect assumptions about the completion of notifications in the io_uring subsystem, potentially causing synchronization issues or mismanagement of resources.

Added: Dec 16, 2025, 6:04 PM
Updated: Dec 16, 2025, 6:04 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
4.0
remediation
7.7
relevance
1.5
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.