Executive brief
libfuse is a widely used library that allows non-privileged users to create their own file systems in Linux. A security flaw in its io_uring component could allow a local attacker to crash file system processes or potentially take full control of the system by executing malicious code. This is particularly relevant in containerized environments like Kubernetes, where standard resource limits can inadvertently trigger the conditions needed for this exploit.
Technical details
A use-after-free (UAF) vulnerability exists in libfuse's io_uring subsystem within the `fuse_uring_start()` function. When thread creation fails (e.g., due to `cgroup pids.max` limits returning EAGAIN), the error path calls `fuse_session_destruct_uring()`, which frees the `fuse_ring` structure, but subsequently stores the dangling pointer in `se->uring.pool`. During session shutdown, the library checks if this pointer is non-NULL and attempts to call the destructor again on the already-freed memory. An attacker can potentially reallocate this heap chunk during the session's lifetime to gain control over function pointers (like `free`, `close`, or `pthread_cancel`) called during destruction. The issue is fixed in version 3.18.2 by properly nullifying the pointer in the error path.
Affected products
- libfuse project libfuse >= 3.18.0, < 3.18.2
- Red Hat Red Hat Enterprise Linux 8 affected
Timeline
- 2026-03-18: patched: libfuse version 3.18.2 released
- 2026-03-19: advisory: GitHub Security Advisory GHSA-qxv7-xrc2-qmfx published
- 2026-03-20: disclosed: CVE-2026-33150 published to NVD
References
- https://github.com/libfuse/libfuse/commit/49fcd891a58f622c098e2ca67d66086f7b213836
- https://github.com/libfuse/libfuse/releases/tag/fuse-3.18.2
- https://github.com/libfuse/libfuse/security/advisories/GHSA-qxv7-xrc2-qmfx
- https://access.redhat.com/security/cve/CVE-2026-33150
- https://bugzilla.redhat.com/show_bug.cgi?id=2449771
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33150.json