In the Linux kernel, the following vulnerability has been resolved:
fs/aio: Check IOCB_AIO_RW before the struct aio_kiocb conversion
The first kiocb_set_cancel_fn() argument may point at a struct kiocb
that is not embedded inside struct aio_kiocb. With the current code,
depending on the compiler, the req->ki_ctx read happens either before
the IOCB_AIO_RW test or after that test. Move the req->ki_ctx read such
that it is guaranteed that the IOCB_AIO_RW test happens first.
Metrics
Affected Vendors & Products
References
History
Mon, 15 Dec 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Debian
Debian debian Linux |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:o:debian:debian_linux:10:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.8:rc6:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.8:rc7:*:*:*:*:*:* |
|
| Vendors & Products |
Debian
Debian debian Linux |
Status: PUBLISHED
Assigner: Linux
Published:
Updated: 2025-05-04T09:05:59.810Z
Reserved: 2024-05-17T12:19:12.343Z
Link: CVE-2024-35815
Updated: 2024-08-02T03:21:47.505Z
Status : Undergoing Analysis
Published: 2024-05-17T14:15:16.077
Modified: 2025-12-15T20:43:18.127
Link: CVE-2024-35815
OpenCVE Enrichment
Updated: 2025-07-12T22:01:16Z