Skip to main content

In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: honor task_work cancellation io_waitid_cb() may run through the… (CVE-2026-81010)

0
Medium
Published: 09/11/2026 (09/11/2026, 21:31:24 UTC)
Source: GCVE Database

Description

A vulnerability in the Linux kernel's io_uring subsystem was resolved involving improper handling of task work cancellation in the io_waitid_cb() callback. The issue occurs when the fallback task work path runs from a kworker thread rather than the original submitting task context, causing the callback to ignore cancellation flags and perform operations relative to an incorrect task context. This could lead to incorrect waitid behavior and potential misuse of signal information. The fix ensures that canceled task work is honored by completing the request with an error and skipping unsafe operations.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/12/2026, 01:19:48 UTC

Technical Analysis

The vulnerability in the Linux kernel's io_uring subsystem relates to the io_waitid_cb() callback ignoring the task work cancellation flag (tw.cancel) when running from a fallback kworker context. Normally, waitid operations depend on the submitting task's context for child process lookup and signal handling. When the fallback path executes outside that context, ignoring cancellation can cause the callback to operate on incorrect task data. The patch modifies io_waitid_cb() to check tw.cancel before proceeding, completing the request with -ECANCELED and avoiding unsafe signal info copying when the task work is canceled.

Potential Impact

If exploited, this flaw could cause the io_uring waitid operation to behave incorrectly by performing child process lookups and signal handling relative to an unintended task context. This may lead to incorrect or unexpected behavior in applications relying on waitid through io_uring, potentially causing erroneous process status reporting or signal handling inconsistencies. No known exploits in the wild have been reported.

Mitigation Recommendations

A fix for this vulnerability has been applied in the Linux kernel. Users should update to the fixed kernel version containing the patch that honors task work cancellation in io_waitid_cb(). No additional mitigation steps are required beyond applying the official kernel update.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-qqff-gjp9-r6f6
Osv Schema Version
1.4.0
Aliases
["CVE-2026-81010"]

Threat ID: 6aa4a02755bf5e2cf5a86b0c

Added to database: 09/12/2026, 00:43:19 UTC

Last enriched: 09/12/2026, 01:19:48 UTC

Last updated: 09/12/2026, 01:19:48 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses