Executive brief
A vulnerability in the Linux kernel's virtiofs file system could allow a local user to cause a system crash. The issue occurs when unmounting certain sub-directories, leading to a memory error known as a use-after-free. This primarily impacts the stability and availability of virtualized environments using virtiofs for shared storage.
Technical details
A use-after-free (UAF) vulnerability exists in the virtiofs component of the Linux kernel. The issue stems from fuse_release_end() calling iput() after the associated super block has already been destroyed during an unmount operation. While the kernel typically waits for the 'num_waiting' counter to reach zero before destroying a super block, this counter is managed per-connection rather than per-superblock, failing to protect individual submount instances. An attacker with local access could trigger this race condition to cause a kernel Oops, resulting in a denial of service. The fix involves reverting to synchronous release requests for cases involving automatic submounts.
Affected products
- Linux Linux 5.10.246 to 5.10.260, 5.15.196 to 5.15.211, 6.1.158 to 6.1.172, 6.6.x, 6.9.x
Timeline
- 2026-05-28: patched: Initial fix developed by Miklos Szeredi
- 2026-07-19: disclosed: CVE-2026-53381 published
References
- https://git.kernel.org/stable/c/06b41351779e9289e8785694ade9042ae85e41ea
- https://git.kernel.org/stable/c/0b809199ff87c44487e516a725dd4be2185712ce
- https://git.kernel.org/stable/c/1cc0e3a0c6499aaaa2f21a4fcbba388486afb25e
- https://git.kernel.org/stable/c/2181a09ba980f142650fb053666350ead4471cfe
- https://git.kernel.org/stable/c/2abfd3ffbd9452f72535d96ff3982b3ab1f8f2f9
- https://git.kernel.org/stable/c/39a2b95e008665c14f84e50ed411d898df7cd11b
- https://git.kernel.org/stable/c/607a1d4c42f649e6197567c0448fd9ebb316cd42