Junglewise Threat Intelligence

CVE-2026-31694: Linux Kernel heap overflow in FUSE fuse_add_dirent_to_cache

CVE-2026-31694 · Severity: high · CVSS 7.8 · Published 2026-05-01

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's FUSE (Filesystem in Userspace) component could allow a malicious storage provider to crash the system or potentially gain unauthorized access. By providing an oversized directory entry, a malicious server can trigger a memory overflow within the kernel. This affects systems using FUSE-based filesystems and could lead to a complete compromise of the operating system's integrity and availability.

Technical details

A heap-based buffer overflow exists in the `fuse_add_dirent_to_cache()` function within `fs/fuse/readdir.c`. The vulnerability occurs because the code calculates a serialized directory entry (dirent) size based on a server-provided `namelen` field but fails to verify if the resulting record exceeds the `PAGE_SIZE` (typically 4 KiB). An attacker controlling a FUSE server can provide a `namelen` of 4095, resulting in a 4120-byte record that overflows the destination page by 24 bytes during a `memcpy()` operation. This can lead to kernel memory corruption, privilege escalation, or a system crash. The issue has been patched by adding a check to reject dirents larger than `PAGE_SIZE`.

Affected products

  • Linux Linux Kernel from 4.20 before 6.6.136, from 6.7 before 6.12.84, from 6.13 before 6.18.25, from 6.19 before 7.0.2

Timeline

  • 2026-04-20: other: Vulnerability fixed in upstream source code
  • 2026-05-01: advisory: CVE-2026-31694 published by kernel.org

References

Related threats