In the Linux kernel, the following vulnerability has been resolved:
iouring/poll: fix signed comparison in iopollgetownership()
iopollgetownership() uses a signed comparison to check whether pollrefs has reached the threshold for the slowpath:
if (unlikely(atomic_read(&req->poll_refs) >= IO_POLL_REF_BIAS))
atomicread() returns int (signed). When IOPOLLCANCELFLAG (BIT(31)) is set in poll_refs, the value becomes negative in signed arithmetic, so the >= 128 comparison always evaluates to false and the slowpath is never taken.
Fix this by casting the atomic_read() result to unsigned int before the comparison, so that the cancel flag is treated as a large positive value and correctly triggers the slowpath.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/52xxx/CVE-2026-52933.json",
"cna_assigner": "Linux"
}