๐Ÿ” CVE Alert

CVE-2026-64267

UNKNOWN 0.0

fuse: avoid 32-bit prune notification count wrap

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: fuse: avoid 32-bit prune notification count wrap FUSE_NOTIFY_PRUNE validates the nodeid payload length with: size - sizeof(outarg) != outarg.count * sizeof(u64) On 32-bit kernels, size_t is also 32 bits, so the daemon-controlled count multiplication can wrap. A prune notification with count 0x20000000 and no nodeid payload passes the check, enters the copy loop, and asks the device copy path to read nodeids that are not present in the userspace write buffer. In QEMU this reaches the fuse_copy_fill() BUG_ON(!err) path. Validate the payload length with array_size() instead. That accepts exactly the same valid messages, but avoids wrapping arithmetic before the copy loop consumes the count.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
3f29d59e92a96d843c2ff10ebfed92ac26878658 < 6e2d84fdeac05bfd858e84a76353fdb84f23a43e 3f29d59e92a96d843c2ff10ebfed92ac26878658 < c78c4b242299bc581e4987e5c2786c6f4760c516 3f29d59e92a96d843c2ff10ebfed92ac26878658 < 54243797cedf55447b4c5d560e8cd709900061ae
Linux / Linux
6.18

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/6e2d84fdeac05bfd858e84a76353fdb84f23a43e git.kernel.org: https://git.kernel.org/stable/c/c78c4b242299bc581e4987e5c2786c6f4760c516 git.kernel.org: https://git.kernel.org/stable/c/54243797cedf55447b4c5d560e8cd709900061ae