CVE-2026-97618
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/09/2026
Última modificación:
25/09/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
io_uring/net: don&#39;t overconsume buffers when using MSG_TRUNC<br />
<br />
When a recv/recvmsg is issued with MSG_TRUNC and the incoming packet is<br />
larger than the provided buffer, the net layer returns the full length<br />
of the packet rather than the number of bytes actually copied into the<br />
buffer. As a result, io_uring advances more of the provided buffer ring<br />
than was actually filled. Use the actual filled region size to consume<br />
the buffer, but still return the full size to preserve MSG_TRUNC<br />
semantics.<br />
<br />
Take care with multishot, because that seems to already truncate the<br />
consumption based on the available payload size.<br />
<br />
This was reported in https://github.com/axboe/liburing/issues/1619.<br />
<br />
[axboe: fold in size_t unsigned fix]


