A memory leak flaw was found in the Linux kernel’s io_uring functionality in how a user registers a buffer ring with IORING_REGISTER_PBUF_RING, mmap() it, and then frees it. This flaw allows a local user to crash or potentially escalate their privileges on the system.
https://bugzilla.redhat.com/show_bug.cgi?id=2254050
https://bugs.chromium.org/p/project-zero/issues/detail?id=2504