Executive brief
A vulnerability in the Linux kernel's FUSE (Filesystem in Userspace) component could allow a local user to access uninitialized memory. This occurs because the system fails to verify if data in the page cache is current before retrieving it. In practice, this could lead to the exposure of sensitive information from previously deleted files or other system processes, though the impact is mitigated on systems that automatically clear memory during allocation.
Technical details
A vulnerability in fs/fuse/dev.c exists where FUSE_NOTIFY_RETRIEVE does not check the 'uptodate' status of memory folios before returning data. Because this notification is designed to return data already in the page cache without waiting for the FUSE daemon, it may inadvertently return folios containing uninitialized data if they are not marked as uptodate. This issue primarily affects systems where CONFIG_INIT_ON_ALLOC_DEFAULT_ON or the init_on_alloc=1 kernel parameter is not enabled. An attacker with local access could potentially exploit this to leak sensitive information from kernel memory. The fix introduces a check using folio_test_uptodate() to ensure only valid data is returned.
Affected products
- Linux Linux Kernel 2.6.36 to 7.1
Timeline
- 2026-05-19: other: Vulnerability reported by Jann Horn
- 2026-06-25: disclosed: CVE published
- 2026-06-19: patched: Fix committed to stable branches