๐Ÿ” CVE Alert

CVE-2026-64259

UNKNOWN 0.0

fuse-uring: make a fuse_req on SQE commit only findable after memcpy

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: fuse-uring: make a fuse_req on SQE commit only findable after memcpy Bad userspace might try to trick us and send commit SQEs request unique / commit-id of requests that are not even send to fuse-server (io_uring_cmd_done() not called) yet. fuse_uring_commit_fetch() ends the fuse request when the ring entry has a wrong state, but that could have caused a use-after-free with the memcpy operations in fuse_uring_send_in_task(). In order to avoid such races the call of fuse_uring_add_to_pq() is moved after the copy operations and just before completing the io-uring request - malicious userspace cannot find the request anymore until all prepration work in fuse-client/kernel is completed. This also moves fuse_uring_add_to_pq() a bit up in the code to avoid a forward declaration. Also not with a preparation commit, to make it easier to back port to older kernels.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
c090c8abae4b6b77a1bee116aa6c385456ebef96 < e1711479e9068ea31b31353a702a51e639c3d059 c090c8abae4b6b77a1bee116aa6c385456ebef96 < a635f427d57e2012102ae4886b48d8955c59fb86 c090c8abae4b6b77a1bee116aa6c385456ebef96 < 1efd3d474fc0ba74dfd984249bca78807d739812
Linux / Linux
6.14

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/e1711479e9068ea31b31353a702a51e639c3d059 git.kernel.org: https://git.kernel.org/stable/c/a635f427d57e2012102ae4886b48d8955c59fb86 git.kernel.org: https://git.kernel.org/stable/c/1efd3d474fc0ba74dfd984249bca78807d739812