Resource exhaustion in Linux kernel - CVE-2026-81009
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in the io_uring query interface when processing a query with an oversized size value. A local user can submit a specially crafted query to cause a denial of service.
The interface is reachable through IORING_REGISTER_QUERY without creating an io_uring ring.