Re: [PATCH v1] io_uring: fix dangling iovec after provided-buffer bundle grow failure

From: Jens Axboe

Date: Mon Jul 06 2026 - 13:14:37 EST


On 7/6/26 11:01 AM, Hao-Yu Yang wrote:
> Sorry, i forgot to cc others mail
>
> I discovered and wrote the PoC myself. Trigger way is
> send1: Submit an IORING_OP_SEND request with four valid
> provided buffers. The system will allocate and cache an
> iovec array (of size 4) for this request and store the
> pointer in kmsg->vec.iovec.
>
> send2: Submit a second send request with 8, and I set
> the fourth passed-in address to point to an invalid address.
> Now kmsg still hold old iovec, but old iovec object have
> been freed.
>
> So this will lead dangling pointer.

Side note: please don't top post, linux mailing lists always reply
under the text for better readability. Top posting turns any kind
of threaded conversation into both a mess, and it's also wasteful.

Great thanks! Want to turn this into a liburing test case? Then we can
include it there as well, and it'd catch both UAF and memory leaks when
run.

--
Jens Axboe