Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-97618

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/09/2026
Última modificación:
25/09/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> io_uring/net: don&amp;#39;t overconsume buffers when using MSG_TRUNC<br /> <br /> When a recv/recvmsg is issued with MSG_TRUNC and the incoming packet is<br /> larger than the provided buffer, the net layer returns the full length<br /> of the packet rather than the number of bytes actually copied into the<br /> buffer. As a result, io_uring advances more of the provided buffer ring<br /> than was actually filled. Use the actual filled region size to consume<br /> the buffer, but still return the full size to preserve MSG_TRUNC<br /> semantics.<br /> <br /> Take care with multishot, because that seems to already truncate the<br /> consumption based on the available payload size.<br /> <br /> This was reported in https://github.com/axboe/liburing/issues/1619.<br /> <br /> [axboe: fold in size_t unsigned fix]

Impacto