CVE-2026-46315: io_uring/waitid: clear waitid info before copying it to userspace
Published Jun 9, 2026
·Updated
In the Linux kernel, the following vulnerability has been resolved:
Affected Software
9 affected componentsFixes available
Linux Linux kernel
Linux Linux kernel>=6.7<6.12.92
Linux Linux kernel>=6.13<6.18.34
Linux Linux kernel>=6.19<7.0.11
Linux Linux kernel=7.1-rc1
Linux Linux kernel=7.1-rc2
Linux Linux kernel=7.1-rc3
Linux Linux kernel=7.1-rc4
debian/linux
6.1.176-16.1.187-16.12.107-17.2.6-17.2.7-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.187-1Fixed in 6.12.107-1Fixed in 7.2.6-1Fixed in 7.2.7-1 - Compensating control
In the Linux kernel io_uring/IORING_OP_WAITID prep path, clear or zero-initialize the waitid result storage (struct io_waitid::info) before copying it to userspace.
Event History
Jun 9, 2026
CVE Published
via MITRE·07:38 AM
Data Sourced
via MITRE·07:38 AM
Description
Data Sourced
via NVD·09:16 AM
RemedyDescriptionSeverityAffected Software
Sep 21, 2026
Data Sourced
via Launchpad·02:53 PM
Description
Sep 24, 2026
Data Sourced
via Ubuntu·02:55 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·02:56 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-46315?
CVE-2026-46315 has a risk rating of 18.
2
How do I fix CVE-2026-46315?
To fix CVE-2026-46315, ensure that you update your Linux kernel to the latest patched version.
3
What software is affected by CVE-2026-46315?
CVE-2026-46315 affects the Linux kernel, specifically the io_uring functionality.
4
What type of vulnerability is CVE-2026-46315?
CVE-2026-46315 is a vulnerability related to the improper handling of waitid information in userspace.
5
When was CVE-2026-46315 published?
CVE-2026-46315 was published on June 9, 2026.