In the Linux kernel, the following vulnerability has been resolved: io_uring/zctx: check chained notif contexts Send zc only links ubuf_info for… (CVE-2025-68317)
A high severity vulnerability identified as CVE-2025-68317 in the Linux kernel's io_uring subsystem has been resolved. The issue involved improper handling of chained notification contexts, where zero-copy (zc) links to ubuf_info were sent only for requests from the same context. This vulnerability could lead to confidentiality, integrity, and availability impacts. The fix addresses ambiguous notification completion assumptions reported by syz tests.
AI Analysis
Technical Summary
CVE-2025-68317 is a vulnerability in the Linux kernel's io_uring subsystem related to the handling of chained notification contexts. The flaw involved sending zero-copy links to ubuf_info only for requests originating from the same context, which was not properly checked, leading to potential security issues. The vulnerability has been resolved by adding checks on chained notification contexts to ensure correct handling and prevent misuse. The CVSS 3.1 vector indicates local attack vector with low complexity, requiring low privileges and no user interaction, with high impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation of this vulnerability could allow a local attacker with low privileges to cause significant confidentiality, integrity, and availability damage within the affected Linux kernel environment. The vulnerability affects the io_uring subsystem's notification context handling, potentially leading to unauthorized data access or system disruption.
Mitigation Recommendations
The vulnerability has been resolved in the Linux kernel. However, no explicit patch links or affected versions are provided in the available data. Users should apply the official Linux kernel updates once available that address CVE-2025-68317. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
In the Linux kernel, the following vulnerability has been resolved: io_uring/zctx: check chained notif contexts Send zc only links ubuf_info for… (CVE-2025-68317)
Description
A high severity vulnerability identified as CVE-2025-68317 in the Linux kernel's io_uring subsystem has been resolved. The issue involved improper handling of chained notification contexts, where zero-copy (zc) links to ubuf_info were sent only for requests from the same context. This vulnerability could lead to confidentiality, integrity, and availability impacts. The fix addresses ambiguous notification completion assumptions reported by syz tests.
CVSS v3.1
Score 7.8high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-68317 is a vulnerability in the Linux kernel's io_uring subsystem related to the handling of chained notification contexts. The flaw involved sending zero-copy links to ubuf_info only for requests originating from the same context, which was not properly checked, leading to potential security issues. The vulnerability has been resolved by adding checks on chained notification contexts to ensure correct handling and prevent misuse. The CVSS 3.1 vector indicates local attack vector with low complexity, requiring low privileges and no user interaction, with high impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation of this vulnerability could allow a local attacker with low privileges to cause significant confidentiality, integrity, and availability damage within the affected Linux kernel environment. The vulnerability affects the io_uring subsystem's notification context handling, potentially leading to unauthorized data access or system disruption.
Mitigation Recommendations
The vulnerability has been resolved in the Linux kernel. However, no explicit patch links or affected versions are provided in the available data. Users should apply the official Linux kernel updates once available that address CVE-2025-68317. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-7p3q-9c8m-84x3
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2025-68317"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a6b72d29c2644c7f8477cd3
Added to database: 07/30/2026, 15:50:42 UTC
Last enriched: 07/30/2026, 18:52:57 UTC
Last updated: 09/10/2026, 19:38:48 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.