In the Linux kernel, the following vulnerability has been resolved:
iouring: fix use-after-free of sq->thread in _iouringshow_fdinfo()
syzbot reports:
BUG: KASAN: slab-use-after-free in getrusage+0x1109/0x1a60 Read of size 8 at addr ffff88810de2d2c8 by task a.out/304
CPU: 0 UID: 0 PID: 304 Comm: a.out Not tainted 6.16.0-rc1 #1 PREEMPT(voluntary) Hardware name: QEMU Ubuntu 24.04 PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 Call Trace: <TASK> dumpstacklvl+0x53/0x70 printreport+0xd0/0x670 ? pfxrawspinlockirqsave+0x10/0x10 ? getrusage+0x1109/0x1a60 kasanreport+0xce/0x100 ? getrusage+0x1109/0x1a60 getrusage+0x1109/0x1a60 ? pfxgetrusage+0x10/0x10 _iouringshowfdinfo+0x9fe/0x1790 ? ksysread+0xf7/0x1c0 ? dosyscall64+0xa4/0x260 ? vsnprintf+0x591/0x1100 ? _pfxiouringshowfdinfo+0x10/0x10 ? pfxvsnprintf+0x10/0x10 ? mutextrylock+0xcf/0x130 ? _pfxmutextrylock+0x10/0x10 ? _pfxshowfdlocks+0x10/0x10 ? iouringshowfdinfo+0x57/0x80 iouringshowfdinfo+0x57/0x80 seqshow+0x38c/0x690 seqreaditer+0x3f7/0x1180 ? inodesetctimecurrent+0x160/0x4b0 seqread+0x271/0x3e0 ? _pfxseqread+0x10/0x10 ? _pfxrawspinlock+0x10/0x10 ? markinodedirty+0x402/0x810 ? selinuxfilepermission+0x368/0x500 ? fileupdatetime+0x10f/0x160 vfsread+0x177/0xa40 ? _pfxhandlemmfault+0x10/0x10 ? _pfxvfsread+0x10/0x10 ? mutexlock+0x81/0xe0 ? _pfxmutexlock+0x10/0x10 ? fdgetpos+0x24d/0x4b0 ksysread+0xf7/0x1c0 ? _pfxksysread+0x10/0x10 ? douseraddrfault+0x43b/0x9c0 dosyscall64+0xa4/0x260 entrySYSCALL64afterhwframe+0x77/0x7f RIP: 0033:0x7f0f74170fc9 Code: 00 c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 8 RSP: 002b:00007fffece049e8 EFLAGS: 00000206 ORIG_RAX: 0000000000000000 RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f0f74170fc9 RDX: 0000000000001000 RSI: 00007fffece049f0 RDI: 0000000000000004 RBP: 00007fffece05ad0 R08: 0000000000000000 R09: 00007fffece04d90 R10: 0000000000000000 R11: 0000000000000206 R12: 00005651720a1100 R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000 </TASK>
Allocated by task 298: kasansavestack+0x33/0x60 kasansavetrack+0x14/0x30 _kasanslaballoc+0x6e/0x70 kmemcacheallocnodenoprof+0xe8/0x330 copyprocess+0x376/0x5e00 createiothread+0xab/0xf0 iosqoffloadcreate+0x9ed/0xf20 iouringsetup+0x12b0/0x1cc0 dosyscall64+0xa4/0x260 entrySYSCALL64after_hwframe+0x77/0x7f
Freed by task 22: kasansavestack+0x33/0x60 kasansavetrack+0x14/0x30 kasansavefreeinfo+0x3b/0x60 _kasanslabfree+0x37/0x50 kmemcachefree+0xc4/0x360 rcucore+0x5ff/0x19f0 handlesoftirqs+0x18c/0x530 runksoftirqd+0x20/0x30 smpbootthreadfn+0x287/0x6c0 kthread+0x30d/0x630 retfromfork+0xef/0x1a0 retfromforkasm+0x1a/0x30
Last potentially related work creation: kasansavestack+0x33/0x60 kasanrecordauxstack+0x8c/0xa0 _callrcucommon.constprop.0+0x68/0x940 _schedule+0xff2/0x2930 _condresched+0x4c/0x80 mutexlock+0x5c/0xe0 iouringdeltctxnode+0xe1/0x2b0 iouringcleantctx+0xb7/0x160 iouringcancelgeneric+0x34e/0x760 doexit+0x240/0x2350 dogroupexit+0xab/0x220 _x64sysexitgroup+0x39/0x40 x64syscall+0x1243/0x1840 dosyscall64+0xa4/0x260 entrySYSCALL64after_hwframe+0x77/0x7f
The buggy address belongs to the object at ffff88810de2cb00 which belongs to the cache task_struct of size 3712 The buggy address is located 1992 bytes inside of freed 3712-byte region [ffff88810de2cb00, ffff88810de2d980)
which is caused by the taskstruct pointed to by sq->thread being released while it is being used in the function _iouringshowfdinfo(). Holding ctx->uringlock does not prevent ehre relase or exit of sq->thread.
Fix this by assigning and looking up ->thread under RCU, and grabbing a reference to the task_struct. This e ---truncated---
[
{
"signature_type": "Function",
"id": "CVE-2025-38106-053215fe",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ac0b8b327a5677dc6fecdf353d808161525b1ff0",
"signature_version": "v1",
"deprecated": false,
"target": {
"function": "io_sq_thread",
"file": "io_uring/sqpoll.c"
},
"digest": {
"function_hash": "204293983043904841838018670966076557372",
"length": 2661.0
}
},
{
"signature_type": "Line",
"id": "CVE-2025-38106-0b71577b",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ac0b8b327a5677dc6fecdf353d808161525b1ff0",
"signature_version": "v1",
"deprecated": false,
"target": {
"file": "io_uring/sqpoll.c"
},
"digest": {
"line_hashes": [
"163738595731698686113293889947045711321",
"202287268428457191984824270173986607558",
"74806615230686458106307494192432154517",
"129940374661106688273095811887925712012",
"11244904571192592877801938445207581089",
"330481901348681839478591882469160989826",
"192699853208892470948987399824307218566",
"130800468709351624592786299015332082424",
"319123027079081443771594119498783836252",
"204865428524013362344974427817734870737",
"108096870251927455857507673195037447687",
"54838431266665302969431548298685735537",
"178158843209589688076062173825408696047"
],
"threshold": 0.9
}
},
{
"signature_type": "Line",
"id": "CVE-2025-38106-1232a2a5",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ac0b8b327a5677dc6fecdf353d808161525b1ff0",
"signature_version": "v1",
"deprecated": false,
"target": {
"file": "io_uring/fdinfo.c"
},
"digest": {
"line_hashes": [
"110340598105054762366414962784614483992",
"46259781348485725670811575919681240610",
"222756327152216957203137024353400319942",
"54120253959154926096571484449341346589",
"254148495012144381181604420202571631324",
"15925680907069589231321093119886279778",
"245680038176624900971453113754955668380",
"196770045204899271422881410747047894197",
"124147479150201091580374340738326948801",
"9629382287448871731941787886450374517",
"24869661426732768936654931870129162505"
],
"threshold": 0.9
}
},
{
"signature_type": "Line",
"id": "CVE-2025-38106-1db5a2e2",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@d0932758a0a77b38ba1b39564f3b7aba12407061",
"signature_version": "v1",
"deprecated": false,
"target": {
"file": "io_uring/fdinfo.c"
},
"digest": {
"line_hashes": [
"110340598105054762366414962784614483992",
"46259781348485725670811575919681240610",
"222756327152216957203137024353400319942",
"54120253959154926096571484449341346589",
"254148495012144381181604420202571631324",
"15925680907069589231321093119886279778",
"245680038176624900971453113754955668380",
"196770045204899271422881410747047894197",
"124147479150201091580374340738326948801",
"9629382287448871731941787886450374517",
"24869661426732768936654931870129162505"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"id": "CVE-2025-38106-343af577",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@af8c13f9ee040b9a287ba246cf0055f7c77b7cc8",
"signature_version": "v1",
"deprecated": false,
"target": {
"function": "io_sq_offload_create",
"file": "io_uring/sqpoll.c"
},
"digest": {
"function_hash": "69577804473389409269564127736483472611",
"length": 2026.0
}
},
{
"signature_type": "Function",
"id": "CVE-2025-38106-3d031ef0",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@d0932758a0a77b38ba1b39564f3b7aba12407061",
"signature_version": "v1",
"deprecated": false,
"target": {
"function": "__io_uring_show_fdinfo",
"file": "io_uring/fdinfo.c"
},
"digest": {
"function_hash": "184782356268570368497204863660397986449",
"length": 4763.0
}
},
{
"signature_type": "Line",
"id": "CVE-2025-38106-4f541907",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@af8c13f9ee040b9a287ba246cf0055f7c77b7cc8",
"signature_version": "v1",
"deprecated": false,
"target": {
"file": "io_uring/sqpoll.c"
},
"digest": {
"line_hashes": [
"163738595731698686113293889947045711321",
"202287268428457191984824270173986607558",
"74806615230686458106307494192432154517",
"129940374661106688273095811887925712012",
"11244904571192592877801938445207581089",
"330481901348681839478591882469160989826",
"192699853208892470948987399824307218566",
"130800468709351624592786299015332082424",
"319123027079081443771594119498783836252",
"204865428524013362344974427817734870737",
"108096870251927455857507673195037447687",
"54838431266665302969431548298685735537",
"178158843209589688076062173825408696047"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"id": "CVE-2025-38106-7b967e97",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ac0b8b327a5677dc6fecdf353d808161525b1ff0",
"signature_version": "v1",
"deprecated": false,
"target": {
"function": "io_sq_offload_create",
"file": "io_uring/sqpoll.c"
},
"digest": {
"function_hash": "163956588032093894647119356324326220445",
"length": 1971.0
}
},
{
"signature_type": "Line",
"id": "CVE-2025-38106-7c4632df",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@d0932758a0a77b38ba1b39564f3b7aba12407061",
"signature_version": "v1",
"deprecated": false,
"target": {
"file": "io_uring/sqpoll.c"
},
"digest": {
"line_hashes": [
"163738595731698686113293889947045711321",
"202287268428457191984824270173986607558",
"74806615230686458106307494192432154517",
"129940374661106688273095811887925712012",
"11244904571192592877801938445207581089",
"330481901348681839478591882469160989826",
"192699853208892470948987399824307218566",
"130800468709351624592786299015332082424",
"319123027079081443771594119498783836252",
"204865428524013362344974427817734870737",
"108096870251927455857507673195037447687",
"54838431266665302969431548298685735537",
"178158843209589688076062173825408696047"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"id": "CVE-2025-38106-97a98053",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@d0932758a0a77b38ba1b39564f3b7aba12407061",
"signature_version": "v1",
"deprecated": false,
"target": {
"function": "io_sq_thread",
"file": "io_uring/sqpoll.c"
},
"digest": {
"function_hash": "204293983043904841838018670966076557372",
"length": 2661.0
}
},
{
"signature_type": "Function",
"id": "CVE-2025-38106-a43472e0",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@af8c13f9ee040b9a287ba246cf0055f7c77b7cc8",
"signature_version": "v1",
"deprecated": false,
"target": {
"function": "io_sq_thread",
"file": "io_uring/sqpoll.c"
},
"digest": {
"function_hash": "129950409085879718573016764453599098999",
"length": 2656.0
}
},
{
"signature_type": "Line",
"id": "CVE-2025-38106-aa372c6b",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@af8c13f9ee040b9a287ba246cf0055f7c77b7cc8",
"signature_version": "v1",
"deprecated": false,
"target": {
"file": "io_uring/fdinfo.c"
},
"digest": {
"line_hashes": [
"40111159349193094519212476382096847871",
"52560257525604332152326674636883190764",
"334264653904066409495160750553483124155",
"54120253959154926096571484449341346589",
"254148495012144381181604420202571631324",
"15925680907069589231321093119886279778",
"245680038176624900971453113754955668380",
"196770045204899271422881410747047894197",
"124147479150201091580374340738326948801",
"9629382287448871731941787886450374517",
"24869661426732768936654931870129162505"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"id": "CVE-2025-38106-b3a1a096",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@d0932758a0a77b38ba1b39564f3b7aba12407061",
"signature_version": "v1",
"deprecated": false,
"target": {
"function": "io_sq_offload_create",
"file": "io_uring/sqpoll.c"
},
"digest": {
"function_hash": "163956588032093894647119356324326220445",
"length": 1971.0
}
},
{
"signature_type": "Function",
"id": "CVE-2025-38106-b83d6a29",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@af8c13f9ee040b9a287ba246cf0055f7c77b7cc8",
"signature_version": "v1",
"deprecated": false,
"target": {
"function": "io_uring_show_fdinfo",
"file": "io_uring/fdinfo.c"
},
"digest": {
"function_hash": "305547813000221148248378098128112437104",
"length": 5305.0
}
},
{
"signature_type": "Function",
"id": "CVE-2025-38106-cac1b63f",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ac0b8b327a5677dc6fecdf353d808161525b1ff0",
"signature_version": "v1",
"deprecated": false,
"target": {
"function": "__io_uring_show_fdinfo",
"file": "io_uring/fdinfo.c"
},
"digest": {
"function_hash": "125055371166606310412823935423414675137",
"length": 4543.0
}
}
]