Executive brief
A vulnerability in the Linux kernel's FUSE (Filesystem in Userspace) component could allow a malicious storage provider to crash the system or potentially gain unauthorized access. By providing an oversized directory entry, a malicious server can trigger a memory overflow within the kernel. This affects systems using FUSE-based filesystems and could lead to a complete compromise of the operating system's integrity and availability.
Technical details
A heap-based buffer overflow exists in the `fuse_add_dirent_to_cache()` function within `fs/fuse/readdir.c`. The vulnerability occurs because the code calculates a serialized directory entry (dirent) size based on a server-provided `namelen` field but fails to verify if the resulting record exceeds the `PAGE_SIZE` (typically 4 KiB). An attacker controlling a FUSE server can provide a `namelen` of 4095, resulting in a 4120-byte record that overflows the destination page by 24 bytes during a `memcpy()` operation. This can lead to kernel memory corruption, privilege escalation, or a system crash. The issue has been patched by adding a check to reject dirents larger than `PAGE_SIZE`.
Affected products
- Linux Linux Kernel from 4.20 before 6.6.136, from 6.7 before 6.12.84, from 6.13 before 6.18.25, from 6.19 before 7.0.2
Timeline
- 2026-04-20: other: Vulnerability fixed in upstream source code
- 2026-05-01: advisory: CVE-2026-31694 published by kernel.org
References
- https://git.kernel.org/stable/c/038e61812fa52ef62bad2cfc96bf37dc0db47c1e
- https://git.kernel.org/stable/c/1d4a517fa90480c52fd452fea2686cd80f773ce2
- https://git.kernel.org/stable/c/3059f9abe7f1ba8fddf3c86c5faa1eeacf07e7d4
- https://git.kernel.org/stable/c/45c05af36311624c1148123caeb011312495d86b
- https://git.kernel.org/stable/c/474ce83c96a55f2eeb14dee2be375eeadfdacdf5
- https://git.kernel.org/stable/c/51a8de6c50bf947c8f534cd73da4c8f0a13e7bed
- https://git.kernel.org/stable/c/7de93abfaae1b2dc94da8a07a36421bd073f1d8f