https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=io_uring
https://www.theregister.com/2025/04/29/linux_io_uring_securi...
But most of the 'off by default' are from ~2023 and not a current concern.
One should evaluate the risk according to their specific use case.
It can be a good idea to disable it of you run untrusted workloads (eg: other people’s containers, sharing the same kernel) but if you have a kernel on a machine (virtual or real) dedicated to your own workload you can pretty much keep using io_uring. There are other technologies to enforce security (eg: selinux emand similar).
But in the case of io_uring, it was outright bypassing other security layers. And while we all like to think we're running trusted services/code, we have to think about supply-chain attacks that may surprise us, or zero days, etc.
> Disabling io_uring because “guy on the internet said so” or “$faang_company says so” is beyond dumb.
I think it’s more like “$faang_company already disabled it in their hosts, so I am out of luck for my containers running on their cloud”