CVE-2026-80920 is a vulnerability in Linux Kernel
Published on September 9, 2026
io_uring: defer eventfd signaling when queued from a wakeup handler
In the Linux kernel, the following vulnerability has been resolved:
io_uring: defer eventfd signaling when queued from a wakeup handler
io_req_local_work_add() signals the CQ ring eventfd inline when it is the
one to push the first entry onto ->work_list. For DEFER_TASKRUN rings that
add is frequently done from a waitqueue wakeup handler, where an
arbitrary waitqueue lock is held.
eventfd_signal_mask() only refuses to recurse when current->in_eventfd
is set, but that bit is set by eventfd_signal_mask() itself. If the wake
chain starts somewhere else, signal goes out inline and can feed back
into epoll.
Add IOU_F_TWQ_IN_WAKE, set it on the task_work add done from the three
waitqueue callbacks, and use it to force io_eventfd_signal() down the
existing call_rcu_hurry() deferral instead of signaling inline.
Products Associated with CVE-2026-80920
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 21a091b970cdbcf3e8ff829234b51be6f9192766 and below e22f4494cc9487d326e5e3067f33dea7c1e442b2 is affected.
- Version 21a091b970cdbcf3e8ff829234b51be6f9192766 and below b6bb334b0e9348887e3e55e1f494b0c3b8fbf59f is affected.
- Version 21a091b970cdbcf3e8ff829234b51be6f9192766 and below 40b6ccf68731809ceb85c6e9f0f8f2ed61c7aa5a is affected.
- Version 21a091b970cdbcf3e8ff829234b51be6f9192766 and below cd305ee3633a45fcf5f3a5d83f99f3cb77d87b6e is affected.
- Version 6.1 is affected.
- Before 6.1 is unaffected.
- Version 6.18.49, <= 6.18.* is unaffected.
- Version 7.1.11, <= 7.1.* is unaffected.
- Version 7.2.1, <= 7.2.* is unaffected.
- Version 7.3-rc1, <= * is unaffected.