CVE-2026-31484
HIGHio_uring/fdinfo: fix OOB read in SQE_MIXED wrap check
Title source: cnaDescription
In the Linux kernel, the following vulnerability has been resolved: io_uring/fdinfo: fix OOB read in SQE_MIXED wrap check __io_uring_show_fdinfo() iterates over pending SQEs and, for 128-byte SQEs on an IORING_SETUP_SQE_MIXED ring, needs to detect when the second half of the SQE would be past the end of the sq_sqes array. The current check tests (++sq_head & sq_mask) == 0, but sq_head is only incremented when a 128-byte SQE is encountered, not on every iteration. The actual array index is sq_idx = (i + sq_head) & sq_mask, which can be sq_mask (the last slot) while the wrap check passes. Fix by checking sq_idx directly. Keep the sq_head increment so the loop still skips the second half of the 128-byte SQE on the next iteration.
Scores
CVSS v3
7.1
EPSS
0.0001
EPSS Percentile
2.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Details
CWE
CWE-125
Status
published
Products (9)
Linux/Linux
< 6.19
Linux/Linux
1cba30bf9fdd6c982708f3587f609a30c370d889 - 5170efd9c344c68a8075dcb8ed38d3f8a60e7ed4
Linux/Linux
1cba30bf9fdd6c982708f3587f609a30c370d889 - ba21ab247a5be5382da7464b95afbe5f0e9aa503
Linux/Linux
6.19
Linux/Linux
6.19.11 - 6.19.*
Linux/Linux
7.0
linux/linux_kernel
6.19
linux/linux_kernel
7.0 rc1 (7 CPE variants)
linux/linux_kernel
6.19.1 - 6.19.11
Published
Apr 22, 2026
Tracked Since
Apr 22, 2026