« Volver al listado

CVE-2026-80810

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

io_uring/rsrc: fix folio size overflow in io_vec_fill_bvec()

io_vec_fill_bvec() computes the folio size with a plain int 1:

imu->folio_shift is unsigned int and comes from folio_shift() of the folio backing the registered buffer, so it can be 32 or more on a 64 bit kernel. Shifting int 1 that far is undefined, and on x86 and arm64 the count is taken modulo 32, so a shift of 34 yields 4 rather than 16G. Every other folio_shift shift in this file already uses 1UL.

The result is that the segment estimate and the fill loop disagree. io_estimate_bvec_size() sizes the bvec array with the real shift:

Leer descripción completaMostrar menos

so a 1M iovec on a 16G folio is charged 2 segments, while io_vec_fill_bvec() then walks the same iovec in folio_size chunks of 4 bytes and writes res_bvec[bvec_idx] a quarter of a million times, past the end of the array it was given. src_bvec is advanced once per iteration as well, so imu->bvec is read past its end at the same time. validate_fixed_range() only checks that the range is inside the registered buffer and does not bound the segment count.

Reaching it needs a folio with a shift of at least 32, which means a gigantic hugetlb page: 16G on arm64 with 64K pages, where CONT_PMD_SHIFT is 34 and hugetlb_add_hstate(CONT_PMD_SHIFT - PAGE_SHIFT) registers that size, and likewise on powerpc. x86_64 tops out at 1G, so a shift of 30, which still fits in int and is unaffected.

Use 1UL, as the rest of the file does.

Detalles técnicos trazas, registros y código del informe original
	unsigned long folio_size = 1 << imu->folio_shift;

	max_segs += (iov[i].iov_len >> shift) + 2;

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80810",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "9ef4cbbcb4ac3786a1a4164507511b76b2a572c5",
              "lessThan": "45c945107e007b1fb73e21cd220277652a45521a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9ef4cbbcb4ac3786a1a4164507511b76b2a572c5",
              "lessThan": "6b308c37fbeba3aa8c634fb1ed53e2f63a5d5a5c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9ef4cbbcb4ac3786a1a4164507511b76b2a572c5",
              "lessThan": "3267d7c8ba51642117f7bdd1ece02b2540668476",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9ef4cbbcb4ac3786a1a4164507511b76b2a572c5",
              "lessThan": "3f3a6a16bbe8bde76532d9415438f8cdef439e5d",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "io_uring/rsrc.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.47",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.11",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.1",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "io_uring/rsrc.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-04T16:18:08.360",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/3267d7c8ba51642117f7bdd1ece02b2540668476",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3f3a6a16bbe8bde76532d9415438f8cdef439e5d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/45c945107e007b1fb73e21cd220277652a45521a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6b308c37fbeba3aa8c634fb1ed53e2f63a5d5a5c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/rsrc: fix folio size overflow in io_vec_fill_bvec()\n\nio_vec_fill_bvec() computes the folio size with a plain int 1:\n\n\tunsigned long folio_size = 1 << imu->folio_shift;\n\nimu->folio_shift is unsigned int and comes from folio_shift() of the\nfolio backing the registered buffer, so it can be 32 or more on a 64 bit\nkernel. Shifting int 1 that far is undefined, and on x86 and arm64 the\ncount is taken modulo 32, so a shift of 34 yields 4 rather than 16G.\nEvery other folio_shift shift in this file already uses 1UL.\n\nThe result is that the segment estimate and the fill loop disagree.\nio_estimate_bvec_size() sizes the bvec array with the real shift:\n\n\tmax_segs += (iov[i].iov_len >> shift) + 2;\n\nso a 1M iovec on a 16G folio is charged 2 segments, while\nio_vec_fill_bvec() then walks the same iovec in folio_size chunks of 4\nbytes and writes res_bvec[bvec_idx] a quarter of a million times, past\nthe end of the array it was given. src_bvec is advanced once per\niteration as well, so imu->bvec is read past its end at the same time.\nvalidate_fixed_range() only checks that the range is inside the\nregistered buffer and does not bound the segment count.\n\nReaching it needs a folio with a shift of at least 32, which means a\ngigantic hugetlb page: 16G on arm64 with 64K pages, where\nCONT_PMD_SHIFT is 34 and hugetlb_add_hstate(CONT_PMD_SHIFT - PAGE_SHIFT)\nregisters that size, and likewise on powerpc. x86_64 tops out at 1G, so\na shift of 30, which still fits in int and is unaffected.\n\nUse 1UL, as the rest of the file does."
    }
  ],
  "lastModified": "2026-09-04T16:18:08.360",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}