PT-2026-26679 · Libfuse · Libfuse
Agabhin
·
Published
2026-03-20
·
Updated
2026-03-27
·
CVE-2026-33179
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
libfuse versions 3.18.0 through 3.18.1
Description
libfuse, the reference implementation of the Linux FUSE, contains a flaw in the
fuse uring init queue function. A NULL pointer dereference and memory leak can occur when setting up the io uring queue, specifically when numa alloc local fails. This can lead to a local user crashing the FUSE daemon or causing resource exhaustion. The traditional /dev/fuse path is not affected; only the io uring transport is vulnerable.Recommendations
Update to version 3.18.2 or later.
Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libfuse