PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72112 Linux CVE debrief

A use-after-free vulnerability was found in the Linux kernel's io_uring subsystem when re-registering an already-bound BPF operations struct. This issue allows a local attacker with CAP_BPF and CAP_PERFMON to potentially escalate privileges. The vulnerability arises from the fact that io_install_bpf() only rejects a second registration on the ctx side and sets the per-map back-pointer ops->priv unconditionally. The struct_ops link path never advances a map past BPF_STRUCT_OPS_STATE_READY, allowing the same io_uring_bpf_ops map to be registered more than once. A later io_uring_enter() on the orphaned ring then calls the dangling ctx->loop_step from io_run_loop() -- a use-after-free of freed executable memory, reachable by a task with CAP_BPF + CAP_PERFMON. Evidence is limited; further verification is needed to confirm affected scope and vendor remediation. Linux kernel developers should verify the presence of this fix in their distributions and test it thoroughly.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-15
Advisory published
2026-08-15
Advisory updated
2026-08-15

Who should care

Linux kernel developers, administrators, and users of systems relying on io_uring and BPF operations should be aware of this vulnerability and take steps to mitigate it. Affected Linux kernel developers should verify the presence of this fix in their distributions and test it thoroughly. Security teams and vulnerability management teams should also be aware of this vulnerability and prioritize patching or mitigation efforts accordingly.

Technical summary

The io_uring subsystem in the Linux kernel did not properly handle re-registration of BPF operations structs. When re-registering an already-bound ops, the code did not reject the operation, leading to a use-after-free vulnerability. An attacker with CAP_BPF and CAP_PERFMON can exploit this to potentially escalate privileges. The vulnerability arises from the fact that io_install_bpf() only rejects a second registration on the ctx side and sets the per-map back-pointer ops->priv unconditionally. The struct_ops link path never advances a map past BPF_STRUCT_OPS_STATE_READY, allowing the same io_uring_bpf_ops map to be registered more than once.

Defensive priority

High

Recommended defensive actions

  • Inventory and verify Linux kernel versions to identify potentially affected systems.
  • Apply vendor patches or updates to address the vulnerability.
  • Implement compensating controls, such as restricting access to CAP_BPF and CAP_PERFMON.
  • Monitor system logs for suspicious activity related to io_uring and BPF operations.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The vulnerability was resolved by rejecting re-registration of an already-bound ops. Evidence is limited; further verification is needed to confirm affected scope and vendor remediation. Linux kernel developers should verify the presence of this fix in their distributions and test it thoroughly. Additional testing and validation are required to ensure that the fix is effective and does not introduce any new vulnerabilities. The io_uring and BPF operations should be closely monitored for any suspicious activity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72112 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72112

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72112 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72112

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/0639ea767fe04c288a8d6cb826100fe3d95d4936

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/3afc64c61ce906a04f073ca350b46de10e8302f9

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.