In the Linux kernel, the following vulnerability has been resolved: io_uring/zcrx: fix user_struct uaf io_free_rbuf_ring() usees a struct user_struct, which io_zcrx_ifq_free() puts it down before destroying the ring.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2026052740-CVE-2026-45995-7e97@gregkh/T