Back

HIGH

Use-after-free in io_uring in Linux Kernel

Published Sep 16, 2022

Description

There exists a use-after-free in io_uring in the Linux kernel. Signalfd_poll() and binder_poll() use a waitqueue whose lifetime is the current task. It will send a POLLFREE notification to all waiters before the queue is freed. Unfortunately, the io_uring poll doesn't handle POLLFREE. This allows a use-after-free to occur if a signalfd or binder fd is polled with io_uring poll, and the waitqueue gets freed. We recommend upgrading past commit fc78b2fc21f10c4c9c4d5d659a685710ffa63659

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Google
Published Sep 16, 2022
Updated Apr 21, 2025
Reserved Sep 12, 2022
CISA Vulnrichment
Updated Apr 21, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 1, 2022
ENISA EUVD
Assigner Google
Published Sep 16, 2022
Updated Apr 21, 2025
Exploited since n/a
EUVD-2022-42594