Linux Kernel io_uring Buffer Accounting Vulnerability
CVE-2025-21686

Currently unrated

Key Information:

Vendor
Linux
Status
Vendor
CVE Published:
10 February 2025

Summary

A vulnerability in the Linux kernel's io_uring implementation allows improper accounting of cloned buffers between different memory management instances. When buffers are cloned from one io_uring instance to another, there can be discrepancies in memory counting. If the first io_uring instance is closed while the second is still active, the second instance may incorrectly decrement memory counters associated with the first, potentially leading to negative values in memory locking. This can disrupt the expected performance and resource management of the system, impacting application stability and security.

Affected Version(s)

Linux 7cc2a6eadcd7a5aa36ac63e6659f5c6138c7f4d2

Linux 7cc2a6eadcd7a5aa36ac63e6659f5c6138c7f4d2

Linux 7cc2a6eadcd7a5aa36ac63e6659f5c6138c7f4d2 < 19d340a2988d4f3e673cded9dde405d727d7e248

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.