Junglewise Threat Intelligence

CVE-2026-53388: Linux Kernel use-after-free in FUSE fuse_try_move_folio

CVE-2026-53388 · Severity: info · CVSS 5.5 · Published 2026-07-19

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's FUSE (Filesystem in Userspace) component could allow a local user to cause a system crash. The issue occurs when the system fails to properly manage memory locks during certain file operations, leading to a 'use-after-free' condition. This primarily impacts system stability and availability.

Technical details

A use-after-free vulnerability exists in the Linux kernel FUSE implementation within the fuse_try_move_folio() function (and its predecessor fuse_try_move_page()). The function unlocks a request on entry but fails to re-acquire the lock on the success path. This creates a race condition where fuse_chan_abort() can end the request and free the associated fuse_io_args while subsequent logic in the copy chain is still accessing them. An attacker with local access could potentially exploit this race to trigger a kernel panic. The fix involves ensuring lock_request() is called before replacing the page cache folio to prevent the arguments from being freed prematurely.

Affected products

  • Linux Linux 2.6.35 to 6.9.x

Timeline

  • 2026-07-19: disclosed
  • 2026-07-19: advisory

References