Database/Kernel, userspace & hypervisor
Linux kernel io_uring: MSG_TRUNC recv over-advances the provided buffer ring
Impact
A recv/recvmsg issued through io_uring with MSG_TRUNC on a packet larger than the supplied buffer makes the kernel advance the provided buffer ring by the full packet length instead of the bytes actually copied. The ring consumer and the kernel then disagree about which buffers hold valid data, so a local process can be handed buffer regions it never had filled and the ring bookkeeping drifts out of sync. On a GPU node this is reachable by any unprivileged workload that uses io_uring networking - which now includes most high-performance inference and data-loader paths - and the consequence is wrong or stale buffer contents inside that process rather than a cross-tenant break by itself. No CVSS score or CWE is attached to the record.
Who can reach it
Local unprivileged user or container workload able to open an io_uring instance and issue recv with MSG_TRUNC. No authentication beyond having a shell or a process on the node; nothing is reachable from the network side.
What to do
Take the stable kernel containing the fix (the commit uses the actually filled region to consume the buffer while still returning the full length for MSG_TRUNC semantics) and reboot each node. The advisory record lists only the stable commits, not fixed release numbers, so match the commit against your vendor kernel. Normal rolling drain-and-reboot per node; no firmware work.
References
Related entries
- Linux kernel io_uring: deferred write accounting deadlocks a task against filesystem freezeCVE-2026-97619 · Linux kernel io_uring/rw (superblock write accounting released from task_work)Unscored
- Linux kernel x86/mm: pmd_modify() drops the dirty bit, losing written data on PMD-mapped THPCVE-2026-97945 · Linux kernel x86/mm pmd_modify() (hardware dirty bit dropped on PMD-mapped THP)Unscored
- Linux kernel powerpc/eeh: recursive locking hangs the EEH handler during PCI error recoveryCVE-2026-97948 · Linux kernel powerpc/eeh (recursive pci_rescan_remove_lock in eeh_rmv_device)Unscored
- Linux LIO iSCSI target: LUN_RESET on a WRITE_PENDING command deadlocks the target worker threadCVE-2026-97951 · Linux kernel SCSI target iSCSI frontend (aborted WRITE_PENDING dataout handling)Unscored
- Linux kernel vhost-vdpa: failed eventfd install leaves an ERR_PTR reachable by the config callbackCVE-2026-97993 · Linux kernel vhost-vdpa (ERR_PTR installed in v->config_ctx by VHOST_VDPA_SET_CONFIG_CALL)Unscored
- Linux kernel vhost-vdpa: queue size is not checked against the device maximum, giving an out-of-bounds descriptor readCVE-2026-97994 · Linux kernel vhost-vdpa (VHOST_SET_VRING_NUM validation)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.