GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel io_uring: MSG_TRUNC recv over-advances the provided buffer ring

UnscoredCVE-2026-97618Kernel, userspace & hypervisorcurated

Impact

A recv/recvmsg issued through io_uring with MSG_TRUNC on a packet larger than the supplied buffer makes the kernel advance the provided buffer ring by the full packet length instead of the bytes actually copied. The ring consumer and the kernel then disagree about which buffers hold valid data, so a local process can be handed buffer regions it never had filled and the ring bookkeeping drifts out of sync. On a GPU node this is reachable by any unprivileged workload that uses io_uring networking - which now includes most high-performance inference and data-loader paths - and the consequence is wrong or stale buffer contents inside that process rather than a cross-tenant break by itself. No CVSS score or CWE is attached to the record.

Who can reach it

Local unprivileged user or container workload able to open an io_uring instance and issue recv with MSG_TRUNC. No authentication beyond having a shell or a process on the node; nothing is reachable from the network side.

What to do

Take the stable kernel containing the fix (the commit uses the actually filled region to consume the buffer while still returning the full length for MSG_TRUNC semantics) and reboot each node. The advisory record lists only the stable commits, not fixed release numbers, so match the commit against your vendor kernel. Normal rolling drain-and-reboot per node; no firmware work.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.