Linux vulnerability

In the Linux kernel, the following vulnerability has been resolved: io_uring: prevent opcode speculation sqe->opcode is used for different tables, make sure we santitise it against speculations.

Published 12 Mar 2025Updated 8 Sep 20268 sources
CVSS 7.8

What happened

In the Linux kernel, the following vulnerability has been resolved: io_uring: prevent opcode speculation sqe->opcode is used for different tables, make sure we santitise it against speculations.

Affected versions

Linux: d3656344fea0339fb0365c8df4d2beba4e0089cd through before 87e9eef43c758da267f6332678058a79764c7eba (git); d3656344fea0339fb0365c8df4d2beba4e0089cd through before 18eae8420081ef8e043ad455937bfb470ef08607 (git); d3656344fea0339fb0365c8df4d2beba4e0089cd through before d261ead565a080e3411b0dd04e6d58a52471cac8 (git); d3656344fea0339fb0365c8df4d2beba4e0089cd through before b9826e3b26ec031e9063f64a7c735449c43955e4 (git); d3656344fea0339fb0365c8df4d2beba4e0089cd through before 506b9b5e8c2d2a411ea8fe361333f5081c56d23a (git); d3656344fea0339fb0365c8df4d2beba4e0089cd through before fdbfd52bd8b85ed6783365ff54c82ab7067bd61b (git); d3656344fea0339fb0365c8df4d2beba4e0089cd through before 1e988c3fe1264708f4f92109203ac5b1d65de50b (git); 5.6; V3.1.6 through before * (custom) Fixed: See vendor advisory.

Why it matters

Review the vendor advisory and exposure of the affected product to determine operational impact.

Detection & mitigation

  • Apply vendor-provided updates or mitigations.
  • Review affected product exposure and access logs.

Public PoC references

No public PoC reference has passed the current publication threshold.