{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-64266","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T15:36:31.775Z","datePublished":"2026-07-25T08:49:15.142Z","dateUpdated":"2026-08-17T04:52:20.108Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-17T04:52:20.108Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: re-lock request before returning from fuse_ref_folio()\n\nfuse_ref_folio() unlocks the request but does not re-lock it before\nreturning. fuse_chan_abort() can end the request and the async end\ncallback (eg fuse_writepage_free()) can free the args while the\nsubsequent copy chain logic after fuse_ref_folio() accesses them,\nleading to use-after-free issues.\n\nFix this by locking the request in fuse_ref_folio() before returning."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - A local attacker reaches the flaw by serving a self-created FUSE mount and invoking splice() on its associated /dev/fuse descriptor.\nAC:L - The attacker controls writeback generation, splice processing, and concurrent connection abort, allowing repeated attempts at the race without an uncontrollable prerequisite.\nPR:L - FUSE supports user-namespace mounts, and an unprivileged mount owner can operate /dev/fuse and abort their own connection without init-namespace root.\nUI:N - The attacker can create and exercise their own FUSE connection without any victim action.\nS:U - Exploitation compromises the kernel within the same operating-system security authority and does not inherently cross a virtualization boundary.\nC:H - The freed argument and folio arrays are subsequently dereferenced, permitting attacker-influenced stale folio pointers and potential arbitrary kernel-memory disclosure through pipe buffers.\nI:H - Heap reclamation can replace the freed folio pointers and loop metadata, enabling attacker-directed memory or refcount operations that may support arbitrary writes and kernel code execution.\nA:H - The repeatable use-after-free and invalid folio operations can cause an oops, panic, or other complete system failure."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/fuse/dev.c"],"versions":[{"version":"c3021629a0d820247ee12b6c5192a1d5380e21c6","lessThan":"1f9156714592356b4fda57beac7eab9c2a462dd3","status":"affected","versionType":"git"},{"version":"c3021629a0d820247ee12b6c5192a1d5380e21c6","lessThan":"5630da218a45ba80f0aba0846cbe8aa655da122b","status":"affected","versionType":"git"},{"version":"c3021629a0d820247ee12b6c5192a1d5380e21c6","lessThan":"1ca605cfa59377f0143fb35b5b01360f37d1b7c4","status":"affected","versionType":"git"},{"version":"c3021629a0d820247ee12b6c5192a1d5380e21c6","lessThan":"0e4a5a000123d81234e27a2f8187688cf608f755","status":"affected","versionType":"git"},{"version":"c3021629a0d820247ee12b6c5192a1d5380e21c6","lessThan":"e6aa539720c3d8def69683ed0c07cf9faea4e8be","status":"affected","versionType":"git"},{"version":"c3021629a0d820247ee12b6c5192a1d5380e21c6","lessThan":"be353caffa8640f5e25fb3714ce8b0cef5e410e5","status":"affected","versionType":"git"},{"version":"c3021629a0d820247ee12b6c5192a1d5380e21c6","lessThan":"65a1c2551f7e16085acbb54aedde1feaa559ba7a","status":"affected","versionType":"git"},{"version":"c3021629a0d820247ee12b6c5192a1d5380e21c6","lessThan":"b5befa80fdbe287a98480effed9564712924add5","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/fuse/dev.c"],"versions":[{"version":"2.6.35","status":"affected"},{"version":"0","lessThan":"2.6.35","status":"unaffected","versionType":"semver"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.35","versionEndExcluding":"5.10.261"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.35","versionEndExcluding":"5.15.212"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.35","versionEndExcluding":"6.1.178"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.35","versionEndExcluding":"6.6.145"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.35","versionEndExcluding":"6.12.96"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.35","versionEndExcluding":"6.18.39"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.35","versionEndExcluding":"7.1.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.35","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/1f9156714592356b4fda57beac7eab9c2a462dd3"},{"url":"https://git.kernel.org/stable/c/5630da218a45ba80f0aba0846cbe8aa655da122b"},{"url":"https://git.kernel.org/stable/c/1ca605cfa59377f0143fb35b5b01360f37d1b7c4"},{"url":"https://git.kernel.org/stable/c/0e4a5a000123d81234e27a2f8187688cf608f755"},{"url":"https://git.kernel.org/stable/c/e6aa539720c3d8def69683ed0c07cf9faea4e8be"},{"url":"https://git.kernel.org/stable/c/be353caffa8640f5e25fb3714ce8b0cef5e410e5"},{"url":"https://git.kernel.org/stable/c/65a1c2551f7e16085acbb54aedde1feaa559ba7a"},{"url":"https://git.kernel.org/stable/c/b5befa80fdbe287a98480effed9564712924add5"}],"title":"fuse: re-lock request before returning from fuse_ref_folio()","x_generator":{"engine":"bippy-1.2.0"}}}}