{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80859","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.797Z","datePublished":"2026-09-04T15:55:13.378Z","dateUpdated":"2026-09-11T09:57:14.427Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-11T09:57:14.427Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: fix missing barrier when checking io-uring readiness\n\nfuse_block_alloc() reads fch->initialized and then fch->io_uring.\nfch->io_uring is set before fch->initialized, ordered by the smp_wmb()\nin fuse_chan_set_intialized(), but fuse_block_alloc() has no matching\nread barrier between the two loads.\n\nThis may lead a CPU to observe fch->initialized=1 but fch->io_uring=0,\nand skip the check that blocks request allocation until the io-uring\nqueues are ready. This can reintroduce the lock-order inversion deadlock\nthat commit 3393ff964e0f prevents.\n\nAdd an smp_rmb() barrier to pair with the smp_wmb() in\nfuse_chan_set_initialized() to prevent this."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/fuse/dev.c"],"versions":[{"version":"3393ff964e0fa5def66570c54a4612bf9df06b76","lessThan":"8974575898cd7a4c818088f102b2e7a0286d3302","status":"affected","versionType":"git"},{"version":"3393ff964e0fa5def66570c54a4612bf9df06b76","lessThan":"dd9c835709f4bb3e4256eea7573e4e6e18f956de","status":"affected","versionType":"git"},{"version":"3393ff964e0fa5def66570c54a4612bf9df06b76","lessThan":"edb310bc27f0ad83e7fd558a3caf1a94ca511654","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/fuse/dev.c"],"versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.14","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.14","versionEndExcluding":"7.2.3"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.14","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/8974575898cd7a4c818088f102b2e7a0286d3302"},{"url":"https://git.kernel.org/stable/c/dd9c835709f4bb3e4256eea7573e4e6e18f956de"},{"url":"https://git.kernel.org/stable/c/edb310bc27f0ad83e7fd558a3caf1a94ca511654"}],"title":"fuse: fix missing barrier when checking io-uring readiness","x_generator":{"engine":"bippy-1.2.0"}}}}