Description: io_uring out of boundary memory access in __io_uaddr_map() References: https://bugzilla.redhat.com/show_bug.cgi?id=2253249 https://patchwork.kernel.org/project/io-uring/patch/20231130194633.649319-2-axboe@kernel.dk/ Notes: carnil> Commit fixes 03d89a2de25b ("io_uring: support for user carnil> allocated memory for rings/sqes") in 6.5-rc1. carnil> For 6.6.y fixed as well in 6.6.5. Bugs: upstream: released (6.7-rc4) [820d070feb668aab5bc9413c285a1dda2a70e076] 6.1-upstream-stable: N/A "Vulnerable code not present" 5.10-upstream-stable: N/A "Vulnerable code not present" 4.19-upstream-stable: N/A "Vulnerable code not present" sid: released (6.6.8-1) 6.1-bookworm-security: N/A "Vulnerable code not present" 5.10-bullseye-security: N/A "Vulnerable code not present" 4.19-buster-security: N/A "Vulnerable code not present"