CyberRota
← Ana sayfaya dön

CVE-2026-46315

UNKNOWN · CVSS N/A EPSS %0.16

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-06-09T09:16:30.330 · Çekilme zamanı: 2026-06-30T12:13:45.319122+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-46315
Severity
UNKNOWN
CVSS
N/A
EPSS
%0.16
Linux

Orijinal NVD Açıklaması

In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: clear waitid info before copying it to userspace IORING_OP_WAITID stores its result fields in struct io_waitid::info and later copies them to userspace siginfo. The prep path initializes the request arguments, but it does not initialize info itself. If the wait operation completes without reporting a child event, the common wait code can return without writing wo_info. In that case io_waitid_finish() still copies iw->info to userspace, exposing stale bytes from the reused io_kiocb command storage. Clear the result storage during prep so the io_uring path matches the regular waitid syscall, which uses a zero-initialized struct waitid_info.