io_uring: defer eventfd signaling when queued from a wakeup handler
Summary
| CVE | CVE-2026-80920 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-09 17:17:47 UTC |
| Updated | 2026-09-09 17:17:47 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
io_uring: defer eventfd signaling when queued from a wakeup handler
io_req_local_work_add() signals the CQ ring eventfd inline when it is the
one to push the first entry onto ->work_list. For DEFER_TASKRUN rings that
add is frequently done from a waitqueue wakeup handler, where an
arbitrary waitqueue lock is held.
eventfd_signal_mask() only refuses to recurse when current->in_eventfd
is set, but that bit is set by eventfd_signal_mask() itself. If the wake
chain starts somewhere else, signal goes out inline and can feed back
into epoll.
Add IOU_F_TWQ_IN_WAKE, set it on the task_work add done from the three
waitqueue callbacks, and use it to force io_eventfd_signal() down the
existing call_rcu_hurry() deferral instead of signaling inline. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 21a091b970cdbcf3e8ff829234b51be6f9192766 e22f4494cc9487d326e5e3067f33dea7c1e442b2 git |
Not specified |
| CNA |
Linux |
Linux |
affected 21a091b970cdbcf3e8ff829234b51be6f9192766 b6bb334b0e9348887e3e55e1f494b0c3b8fbf59f git |
Not specified |
| CNA |
Linux |
Linux |
affected 21a091b970cdbcf3e8ff829234b51be6f9192766 40b6ccf68731809ceb85c6e9f0f8f2ed61c7aa5a git |
Not specified |
| CNA |
Linux |
Linux |
affected 21a091b970cdbcf3e8ff829234b51be6f9192766 cd305ee3633a45fcf5f3a5d83f99f3cb77d87b6e git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.1 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.1 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.49 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.11 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.1 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/b6bb334b0e9348887e3e55e1f494b0c3b8fbf59f |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/cd305ee3633a45fcf5f3a5d83f99f3cb77d87b6e |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/40b6ccf68731809ceb85c6e9f0f8f2ed61c7aa5a |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/e22f4494cc9487d326e5e3067f33dea7c1e442b2 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.