In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: honor task_work cancellation io_waitid_cb() may run through the… (CVE-2026-81010)
A vulnerability in the Linux kernel's io_uring subsystem was resolved involving improper handling of task work cancellation in the io_waitid_cb() callback. The issue occurs when the fallback task work path runs from a kworker thread rather than the original submitting task context, causing the callback to ignore cancellation flags and perform operations relative to an incorrect task context. This could lead to incorrect waitid behavior and potential misuse of signal information. The fix ensures that canceled task work is honored by completing the request with an error and skipping unsafe operations.
AI Analysis
Technical Summary
The vulnerability in the Linux kernel's io_uring subsystem relates to the io_waitid_cb() callback ignoring the task work cancellation flag (tw.cancel) when running from a fallback kworker context. Normally, waitid operations depend on the submitting task's context for child process lookup and signal handling. When the fallback path executes outside that context, ignoring cancellation can cause the callback to operate on incorrect task data. The patch modifies io_waitid_cb() to check tw.cancel before proceeding, completing the request with -ECANCELED and avoiding unsafe signal info copying when the task work is canceled.
Potential Impact
If exploited, this flaw could cause the io_uring waitid operation to behave incorrectly by performing child process lookups and signal handling relative to an unintended task context. This may lead to incorrect or unexpected behavior in applications relying on waitid through io_uring, potentially causing erroneous process status reporting or signal handling inconsistencies. No known exploits in the wild have been reported.
Mitigation Recommendations
A fix for this vulnerability has been applied in the Linux kernel. Users should update to the fixed kernel version containing the patch that honors task work cancellation in io_waitid_cb(). No additional mitigation steps are required beyond applying the official kernel update.
In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: honor task_work cancellation io_waitid_cb() may run through the… (CVE-2026-81010)
Description
A vulnerability in the Linux kernel's io_uring subsystem was resolved involving improper handling of task work cancellation in the io_waitid_cb() callback. The issue occurs when the fallback task work path runs from a kworker thread rather than the original submitting task context, causing the callback to ignore cancellation flags and perform operations relative to an incorrect task context. This could lead to incorrect waitid behavior and potential misuse of signal information. The fix ensures that canceled task work is honored by completing the request with an error and skipping unsafe operations.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in the Linux kernel's io_uring subsystem relates to the io_waitid_cb() callback ignoring the task work cancellation flag (tw.cancel) when running from a fallback kworker context. Normally, waitid operations depend on the submitting task's context for child process lookup and signal handling. When the fallback path executes outside that context, ignoring cancellation can cause the callback to operate on incorrect task data. The patch modifies io_waitid_cb() to check tw.cancel before proceeding, completing the request with -ECANCELED and avoiding unsafe signal info copying when the task work is canceled.
Potential Impact
If exploited, this flaw could cause the io_uring waitid operation to behave incorrectly by performing child process lookups and signal handling relative to an unintended task context. This may lead to incorrect or unexpected behavior in applications relying on waitid through io_uring, potentially causing erroneous process status reporting or signal handling inconsistencies. No known exploits in the wild have been reported.
Mitigation Recommendations
A fix for this vulnerability has been applied in the Linux kernel. Users should update to the fixed kernel version containing the patch that honors task work cancellation in io_waitid_cb(). No additional mitigation steps are required beyond applying the official kernel update.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-qqff-gjp9-r6f6
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-81010"]
Threat ID: 6aa4a02755bf5e2cf5a86b0c
Added to database: 09/12/2026, 00:43:19 UTC
Last enriched: 09/12/2026, 01:19:48 UTC
Last updated: 09/12/2026, 01:19:48 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.