CVE-2026-31484

medium Red Hat
Published: April 22, 2026 (22 days ago)
Last Modified: April 22, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in the Linux kernel. A local user could potentially exploit an out-of-bounds read vulnerability in the `io_uring/fdinfo` component, specifically within the `__io_uring_show_fdinfo()` function. This issue arises from an incorrect wrap check when processing 128-byte Submission Queue Entries (SQEs) on an `IORING_SETUP_SQE_MIXED` ring, which can cause the array index to exceed its allocated boundary. Successful exploitation of this flaw could lead to information disclosure or system instability.

CWE

CWE-1285

Affected Products

Red Hat Enterprise Linux 10Red Hat Enterprise Linux 6Red Hat Enterprise Linux 7Red Hat Enterprise Linux 8Red Hat Enterprise Linux 9

References