{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.12-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  io_uring/cmd: fix iovec leak when the async cmd is not recycled  An io_async_cmd carries an iovec array in -\u003evec.iovec, allocated when the vec has to grow and kept across recycling through ctx-\u003ecmd_cache.  On two paths nothing frees it and io_clean_op()'s kfree(req-\u003easync_data) drops the io_async_cmd without it.  io_req_uring_cleanup() clears the async data flags only when io_alloc_cache_put() succeeds, and the cache holds IO_ALLOC_CACHE_MAX == 128 entries, so once it is full the put fails and the vec is left behind. An NVMe passthrough workload gets there without doing anything unusual: nvme_uring_cmd_io() returns -EIOCBQUEUED, so the io_async_cmd stays attached for the lifetime of the command and the live object count tracks the queue depth.  Above 128 the puts start failing.  -\u003ecleanup is the last chance to free an inherited vec, since io_req_uring_cleanup() returns early for an io-wq issued command and is not called at all for one completed without ever being issued.  But io_clean_op() calls -\u003ecleanup only if REQ_F_NEED_CLEANUP is set, and for uring_cmd that happens only where the vec has to grow, so a command reusing a large enough cached vec never sets it.  io_rw_alloc_async() and io_msg_alloc_async() flag an inherited vec for exactly this reason; io_uring_cmd_prep() does not.  Flag an inherited vec in io_uring_cmd_prep(), and free the vec when the cache put fails, as io_req_rw_cleanup() does.  The leak is invisible under KASAN, where io_alloc_cache_vec_kasan() frees the vec unconditionally.",
  "id": "DEBIAN-CVE-2026-80811",
  "modified": "2026-09-14T16:47:35.451479463Z",
  "published": "2026-09-04T16:18:08.497Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-80811"
    }
  ],
  "upstream": [
    "CVE-2026-80811"
  ]
}