Out-of-bounds write in Linux kernel - CVE-2026-80810
Published: September 5, 2026
Vulnerability details
The vulnerability allows a local user to cause out-of-bounds reads and writes.
The vulnerability exists due to an integer shift overflow in io_vec_fill_bvec() in io_uring/rsrc.c when processing an iovec associated with a registered buffer backed by a folio with a shift of at least 32. A local user can submit crafted iovecs to cause out-of-bounds reads and writes.
On arm64 systems with 64K pages, the required folio can be a 16G hugetlb page; powerpc systems can also support the required folio size.