Descriptionio_uring use work_flags to determine which identity need to grab from the calling process to make sure it is consistent with the calling process when executing IORING_OP. Some operations are missing some types, which can lead to incorrect reference counts which can then lead to a double free. We recommend upgrading the kernel past commit df3f3bb5059d20ef094d6b2f0256c4bf4127a859
Source PackageReleaseVersionStatus
linux (PTS)buster4.19.235-1fixed
buster (security)4.19.249-2fixed
bullseye (security)5.10.136-1fixed
bookworm, sid5.18.16-1fixed

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
linuxsourcebuster(not affected)


