Answer in brief
CVE-2026-46315 records a Medium severity (CVSS 5.5) vulnerability in io_uring/waitid: clear waitid info before copying it to userspace. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f31ecf671ddc498f20219453395794ff2383e06b <954518e5a4a5efc5033253f6e36fc7b9f98363a3 || >=f31ecf671ddc498f20219453395794ff2383e06b <b737c6612c60c23b40a9f31749b99e6f61943847 || >=f31ecf671ddc498f20219453395794ff2383e06b <4d2a0de611ab60d02fc768ae0cd5918b16bd5474 || >=f31ecf671ddc498f20219453395794ff2383e06b <93d93f5f8da791e98159795c6ef683f45bd95d13 | 954518e5a4a5efc5033253f6e36fc7b9f98363a3, b737c6612c60c23b40a9f31749b99e6f61943847, 4d2a0de611ab60d02fc768ae0cd5918b16bd5474, 93d93f5f8da791e98159795c6ef683f45bd95d13 |
| Linux/Linuxgeneric | 6.7 | Not reported |
Published upstream
Jun 9, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jul 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 7, 2026
In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: clear waitid info before copying it to userspace IORING_OP_WAITID stores its result fields in struct io_waitid::info and later copies them to userspace siginfo. The prep path initializes the request arguments, but it does not initialize info itself. If the wait operation completes without reporting a child event, the common wait code can return without writing wo_info. In that case io_waitid_finish() still copies iw->info to userspace, exposing stale bytes from the reused io_kiocb command storage. Clear the result storage during prep so the io_uring path matches the regular waitid syscall, which uses a zero-initialized struct waitid_info.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-46315 records a Medium severity (CVSS 5.5) vulnerability in io_uring/waitid: clear waitid info before copying it to userspace. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f31ecf671ddc498f20219453395794ff2383e06b <954518e5a4a5efc5033253f6e36fc7b9f98363a3 || >=f31ecf671ddc498f20219453395794ff2383e06b <b737c6612c60c23b40a9f31749b99e6f61943847 || >=f31ecf671ddc498f20219453395794ff2383e06b <4d2a0de611ab60d02fc768ae0cd5918b16bd5474 || >=f31ecf671ddc498f20219453395794ff2383e06b <93d93f5f8da791e98159795c6ef683f45bd95d13 | 954518e5a4a5efc5033253f6e36fc7b9f98363a3, b737c6612c60c23b40a9f31749b99e6f61943847, 4d2a0de611ab60d02fc768ae0cd5918b16bd5474, 93d93f5f8da791e98159795c6ef683f45bd95d13 |
| Linux/Linuxgeneric | 6.7 | Not reported |
Published upstream
Jun 9, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jul 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 7, 2026
In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: clear waitid info before copying it to userspace IORING_OP_WAITID stores its result fields in struct io_waitid::info and later copies them to userspace siginfo. The prep path initializes the request arguments, but it does not initialize info itself. If the wait operation completes without reporting a child event, the common wait code can return without writing wo_info. In that case io_waitid_finish() still copies iw->info to userspace, exposing stale bytes from the reused io_kiocb command storage. Clear the result storage during prep so the io_uring path matches the regular waitid syscall, which uses a zero-initialized struct waitid_info.
Quoted source text, attributed separately from HOL analysis.