๐Ÿ” CVE Alert

CVE-2026-33150

HIGH 7.8

Use After Free in libfuse

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
4th

libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a use-after-free vulnerability in the io_uring subsystem of libfuse allows a local attacker to crash FUSE filesystem processes and potentially execute arbitrary code. When io_uring thread creation fails due to resource exhaustion (e.g., cgroup pids.max), fuse_uring_start() frees the ring pool structure but stores the dangling pointer in the session state, leading to a use-after-free when the session shuts down. The trigger is reliable in containerized environments where cgroup pids.max limits naturally constrain thread creation. This issue has been patched in version 3.18.2.

CWE CWE-416
Vendor libfuse
Product libfuse
Published Mar 20, 2026
Last Updated Mar 27, 2026
Stay Ahead of the Next One

Get instant alerts for libfuse libfuse

Be the first to know when new high vulnerabilities affecting libfuse libfuse are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

libfuse / libfuse
>= 3.18.0, < 3.18.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/libfuse/libfuse/security/advisories/GHSA-qxv7-xrc2-qmfx github.com: https://github.com/libfuse/libfuse/commit/49fcd891a58f622c098e2ca67d66086f7b213836 github.com: https://github.com/libfuse/libfuse/releases/tag/fuse-3.18.2