CVE-2026-81010
CVE CVE-2026-81010EUVD EUVD-2026-76333Published 2026-09-11T19:43:00.000ZLast changed 2026-09-14T11:59:42.000ZCVSS 7.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: honor task_work cancellation io_waitid_cb() may run through the fallback task_work path when task_work_add() can no longer queue work to the originating task. The fallback runs from a kworker and io_uring marks such task work as canceled through tw.cancel. io_waitid_cb() currently ignores tw.cancel and calls __do_wait(). waitid is task-context dependent: __do_wait() performs child lookup relative to current, and the retry path also uses current->signal->wait_chldexit. If the callback runs from the fallback kworker, current is therefore not the task that submitted the request. Honor tw.cancel before entering __do_wait(). Complete the request with -ECANCELED and skip the siginfo copy, since canceled task work may run without the submitting task's userspace execution context. Keep the existing siginfo handling for normal waitid completion and explicit cancellation.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux f31ecf671ddc498f20219453395794ff2383e06b <7bc98e2de8c58a2bfaf0f540eb096a386ecfc96c; patch: 7.2.4; patch: 0; patch: 7.3-rc1; f31ecf671ddc498f20219453395794ff2383e06b <0879697520abda2383ed7be40572ad583b5c4b02; patch: 6.18.52; 6.7; f31ecf671ddc498f20219453395794ff2383e06b <14572de82e5022899e5856008bc9cac97004a88c
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.