CVE-2021-41073 is a local privilege escalation vulnerability in the Linux kernel io_uring subsystem, affecting Linux kernel 5.10 through 5.14.6. The bug is in the handling of provided buffers for I/O requests in fs/io_uring.c, specifically in the interaction between io_rw_buffer_select(), loop_rw_iter(), io_put_rw_kbuf(), and io_put_kbuf(). When IOSQE_BUFFER_SELECT / IORING_OP_PROVIDE_BUFFERS is used, req->rw.addr can hold a kernel pointer to an io_buffer object rather than a user pointer. loop_rw_iter() incorrectly advances req->rw.addr as though it were a user-space buffer pointer, and later io_put_rw_kbuf() treats the modified value as an io_buffer pointer and passes it to io_put_kbuf(), which ultimately calls kfree() on the corrupted pointer. This results in an incorrect free / invalid free of a kernel buffer, effectively allowing a kmalloc-32 object to be freed at a user-controlled offset. Public analysis describes turning this primitive into a use-after-free and then into reliable local privilege escalation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux kernel vulnerability discussed in the context of disclosure handling and omission of exploitability details in the fix commit.
An incorrect free vulnerability in the Linux kernel io_uring subsystem when provided buffers are used, enabling kernel heap corruption and local privilege escalation exploit development.
A Linux kernel io_uring local privilege escalation vulnerability caused by type confusion in handling provided buffers, leading to an invalid free/use-after-free primitive and enabling kernel privilege escalation.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.