https://seclists.org/oss-sec/2026/q2/429: CVE quest: io_uring zcrx felist OOB write
Published May 7, 2026
·Updated
Affected Software
1 affected component
The Linux Foundation Linux kernel (io_uring/zcrx)>=6.15<770594e (commit Apr 21 2026)
Frequently Asked Questions
1
What is the severity of CVE-2026-xxxx?
CVE-2026-xxxx is classified as a high severity out-of-bounds write vulnerability in the Linux kernel's io_uring subsystem.
2
How do I fix CVE-2026-xxxx?
To fix CVE-2026-xxxx, update your Linux kernel to version 6.19.12 or later, where the vulnerability has been patched.
3
What systems are affected by CVE-2026-xxxx?
CVE-2026-xxxx affects all Linux kernel versions prior to 6.19.12 that utilize the io_uring zcrx functionality.
4
What impact does CVE-2026-xxxx have on Linux systems?
The impact of CVE-2026-xxxx includes potential data corruption and possible escalation of privileges due to unauthorized memory access.
5
Is there a workaround for CVE-2026-xxxx until I can update?
A possible workaround for CVE-2026-xxxx is to disable the io_uring feature if it is not essential for your operations.