In the Linux kernel, the following vulnerability has been resolved:io_uring/msg_ring: ensure io_kiocb freeing is deferred for RCUsyzbot reports that defer/local task_work adding via msg_ring can hita request that has been freed:CPU: 1 UID: 0 PID: 19356 Comm: iou-wrk-19354 Not tainted 6.16.0-rc4-syzkaller-00108-g17bbde2e1716 #0 PREEMPT(full)Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025Call Trace:
No PoCs from references.
- https://github.com/w4zu/Debian_security