Local privilege escalation via io_uring task-exit race
Published Dec 29, 2024 · Updated Aug 5, 2026
Use-after-free in Linux io_uring 5.14 and later affected branches allows local users to gain kernel privileges through a task-exit race. io_queue_iowq() queues task work after teardown has killed and cleared io_wq, so concurrent ring closure and task exit dereference freed or null queue state. Unprivileged io_uring access and control of ring closure and process exit are sufficient; exploitation can elevate privileges, crash the kernel, or hang the ring.
Summary
What happened
Use-after-free in Linux io_uring 5.14 and later affected branches allows local users to gain kernel privileges through a task-exit race. io_queue_iowq() queues task work after teardown has killed and cleared io_wq, so concurrent ring closure and task exit dereference freed or null queue state. Unprivileged io_uring access and control of ring closure and process exit are sufficient; exploitation can elevate privileges, crash the kernel, or hang the ring.
The record
- CVE
- CVE-2024-56709
- Published
- Dec 29, 2024
- Updated
- Aug 5, 2026
- Vendor
- The Linux Kernel Organization
- Product
- Linux
- Classifications
- T1499, T1068
- Attack vector
- local
- Privileges
- authenticated
Timeline
How it unfolded
- Dec 29, 2024CVE publishedPublication date reported by the CVE source.
- Aug 5, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=5.14
- Affected versionversion=773af69121ecc6c53d192661af8d53bb3db028ae <2ca94c8de36091067b9ce7527ae8db3812d38781
- Affected versionversion=773af69121ecc6c53d192661af8d53bb3db028ae <4f95a2186b7f2af09331e1e8069bcaf34fe019cf
- Affected versionversion=773af69121ecc6c53d192661af8d53bb3db028ae <534d59ab38010aada88390db65985e65d0de7d9e
- Affected versionversion=773af69121ecc6c53d192661af8d53bb3db028ae <dbd2ca9367eb19bc5e269b8c58b0b1514ada9156
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo