{"api_version":"1","generated_at":"2026-08-29T12:12:53+00:00","cve":"CVE-2026-80713","urls":{"html":"https://cve.report/CVE-2026-80713","api":"https://cve.report/api/cve/CVE-2026-80713.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-80713","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-80713"},"summary":{"title":"io_uring: preserve task restrictions across exec","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring: preserve task restrictions across exec\n\nPer-task restrictions apply to all rings created by a task. Once\ninstalled, they should not be dropped across exec.\n\nFor a task that has used io_uring, the exec cancellation path calls\n__io_uring_free(). This frees both the task context and the per-task\nrestriction, so a ring created after exec is unrestricted.\n\nSplit task context cleanup into io_uring_free_tctx(), and use it from\nthe exec cancellation path. Keep __io_uring_free() for final task\ncleanup, where both the context and restriction are released.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-28 08:16:56","updated_at":"2026-08-29 07:16:52"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"8.4","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"8.4","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","data":{"baseScore":8.4,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/fcef9325afeecced693a7438e975e4a3f8e2716f","name":"https://git.kernel.org/stable/c/fcef9325afeecced693a7438e975e4a3f8e2716f","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/bc0e8faf90e776a2f1f3967a04e8091e6bdb4977","name":"https://git.kernel.org/stable/c/bc0e8faf90e776a2f1f3967a04e8091e6bdb4977","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80713","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80713","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected ed82f35b926b2e505c14b7006473614b8f58b4f4 fcef9325afeecced693a7438e975e4a3f8e2716f git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected ed82f35b926b2e505c14b7006473614b8f58b4f4 bc0e8faf90e776a2f1f3967a04e8091e6bdb4977 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7.0","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.0 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.8 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"80713","cve":"CVE-2026-80713","epss":"0.001450000","percentile":"0.040380000","score_date":"2026-08-28","updated_at":"2026-08-29 00:12:17"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["io_uring/cancel.c","io_uring/tctx.c","io_uring/tctx.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"fcef9325afeecced693a7438e975e4a3f8e2716f","status":"affected","version":"ed82f35b926b2e505c14b7006473614b8f58b4f4","versionType":"git"},{"lessThan":"bc0e8faf90e776a2f1f3967a04e8091e6bdb4977","status":"affected","version":"ed82f35b926b2e505c14b7006473614b8f58b4f4","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["io_uring/cancel.c","io_uring/tctx.c","io_uring/tctx.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"7.0"},{"lessThan":"7.0","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.8","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.8","versionStartIncluding":"7.0","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"7.0","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring: preserve task restrictions across exec\n\nPer-task restrictions apply to all rings created by a task. Once\ninstalled, they should not be dropped across exec.\n\nFor a task that has used io_uring, the exec cancellation path calls\n__io_uring_free(). This frees both the task context and the per-task\nrestriction, so a ring created after exec is unrestricted.\n\nSplit task context cleanup into io_uring_free_tctx(), and use it from\nthe exec cancellation path. Keep __io_uring_free() for final task\ncleanup, where both the context and restriction are released."}],"metrics":[{"cvssV3_1":{"baseScore":8.4,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - The flaw is reached only via local io_uring syscalls (io_uring_setup/io_uring_register) and execve(); fs/exec.c calls io_uring_task_cancel() which invokes the buggy __io_uring_free() path, and per kernel guidance io_uring is Local not Network.\nAC:L - The attacker fully controls the trigger by calling io_uring_setup() to create a task context then execve(); exec deterministically runs io_uring_cancel_generic(true) and frees per-task restrictions without races, special memory layout, or other uncontrollable conditions.\nPR:L - Exploitation requires only an unprivileged local process that had per-task io_uring restrictions installed by a parent/sandbox; the attacker needs no init-namespace CAP_SYS_ADMIN and can use io_uring unless blocked by sysctl or LSM policy.\nUI:N - No victim interaction is required; the confined attacker process itself performs io_uring_setup and execve to drop restrictions, then io_uring_setup again to obtain an unrestricted ring without administrator or other-user action.\nS:C - Per-task io_uring restrictions are a confinement policy enforced by a separate sandbox/parent authority; clearing them across exec lets post-exec code exceed that policy and access kernel interfaces explicitly withheld, crossing the intended sandbox security boundary.\nC:H - Dropping restrictions re-enables blocked io_uring SQEs, register operations, and BPF filters, including IORING_OP_URING_CMD and read-oriented ops against kernel/driver interfaces denied by policy, enabling disclosure beyond the confinement authority's intent.\nI:H - Bypass restores the full unrestricted io_uring opcode and register surface (writes, open/link ops, IORING_OP_URING_CMD, buffer/file registration), allowing post-exec integrity-affecting kernel and driver interactions explicitly denied by per-task restrictions.\nA:N - The vulnerability only incorrectly frees restriction metadata during exec cleanup; it does not directly cause kernel panics, oopses, deadlocks, or hangs, so there is no availability impact from the bug itself."}]}],"providerMetadata":{"dateUpdated":"2026-08-29T06:22:29.500Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/fcef9325afeecced693a7438e975e4a3f8e2716f"},{"url":"https://git.kernel.org/stable/c/bc0e8faf90e776a2f1f3967a04e8091e6bdb4977"}],"title":"io_uring: preserve task restrictions across exec","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-80713","datePublished":"2026-08-28T06:53:12.438Z","dateReserved":"2026-08-26T14:34:25.788Z","dateUpdated":"2026-08-29T06:22:29.500Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-28 08:16:56","lastModifiedDate":"2026-08-29 07:16:52","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2,"impactScore":5.8}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"80713","Ordinal":"1","Title":"io_uring: preserve task restrictions across exec","CVE":"CVE-2026-80713","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"80713","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring: preserve task restrictions across exec\n\nPer-task restrictions apply to all rings created by a task. Once\ninstalled, they should not be dropped across exec.\n\nFor a task that has used io_uring, the exec cancellation path calls\n__io_uring_free(). This frees both the task context and the per-task\nrestriction, so a ring created after exec is unrestricted.\n\nSplit task context cleanup into io_uring_free_tctx(), and use it from\nthe exec cancellation path. Keep __io_uring_free() for final task\ncleanup, where both the context and restriction are released.","Type":"Description","Title":"io_uring: preserve task restrictions across exec"}]}}}