PT-2026-64480 · Linux · Linux

CVE-2026-64259

·

Published

2026-07-25

·

Updated

2026-07-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
fuse-uring: make a fuse req on SQE commit only findable after memcpy
Bad userspace might try to trick us and send commit SQEs request unique / commit-id of requests that are not even send to fuse-server (io uring cmd done() not called) yet.
fuse uring commit fetch() ends the fuse request when the ring entry has a wrong state, but that could have caused a use-after-free with the memcpy operations in fuse uring send in task(). In order to avoid such races the call of fuse uring add to pq() is moved after the copy operations and just before completing the io-uring request - malicious userspace cannot find the request anymore until all prepration work in fuse-client/kernel is completed.
This also moves fuse uring add to pq() a bit up in the code to avoid a forward declaration. Also not with a preparation commit, to make it easier to back port to older kernels.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-64259

Affected Products

Linux