CVE-2026-31484

Description

A flaw was found in the Linux kernel. A local user could potentially exploit an out-of-bounds read vulnerability in the io_uring/fdinfo component, specifically within the __io_uring_show_fdinfo() function. This issue arises from an incorrect wrap check when processing 128-byte Submission Queue Entries (SQEs) on an IORING_SETUP_SQE_MIXED ring, which can cause the array index to exceed its allocated boundary. Successful exploitation of this flaw could lead to information disclosure or system instability.

Understanding the Weakness (CWE)

Other

Technical Impact: Varies by Context

Frequently Asked Questions

Want to get errata notifications? Sign up here.