Researchers disclosed CVE-2021-20226, a reference-counting bug in the Linux kernel's io_uring subsystem that can allow local privilege escalation to root. The flaw stems from io_uring worker threads retaining and later using a pointer to current->files without properly incrementing the files_struct reference count, creating unsafe conditions during asynchronous file-descriptor operations.
Technical analysis showed the bug can lead to a use-after-free involving struct file, particularly when fdget() does not increment a file object's reference count because files_struct->count equals 1 and a worker or calling thread closes the descriptor. Researchers said the issue affects newer Linux kernels that include io_uring, noted possible exploitation paths involving asynchronous workers, file-descriptor table reuse, and interaction with execve and privileged processes, and reported that the vulnerability was fixed by a kernel commit that correctly increments the files_struct reference count.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Flatt Security released a detailed write-up explaining the bug's root cause, exploitation conditions, and the kernel commit that fixed it.
Zero Day Initiative published a blog advisory describing CVE-2021-20226, a reference-counting bug in the Linux kernel io_uring subsystem.
The issue was fixed in the Linux kernel by commit 0f2122045b946241a9e549c2a76cea54fa58a7ff, which increments the files_struct reference count appropriately.
The vulnerability was reported to the vendor via the Zero Day Initiative and tracked as ZDI-2021-001.
Flatt Security researcher Shiga (@Ga_ryo_) discovered a reference-counting flaw in the Linux kernel io_uring subsystem that can lead to local privilege escalation to root under certain conditions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
flatt.tech
Open sourcezerodayinitiative.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.