Executive brief
A vulnerability in the Linux kernel's FUSE (Filesystem in Userspace) component could allow a local user to cause a system crash. The issue occurs when the system fails to properly manage memory locks during certain file operations, leading to a 'use-after-free' condition. This primarily impacts system stability and availability.
Technical details
A use-after-free vulnerability exists in the Linux kernel FUSE implementation within the fuse_try_move_folio() function (and its predecessor fuse_try_move_page()). The function unlocks a request on entry but fails to re-acquire the lock on the success path. This creates a race condition where fuse_chan_abort() can end the request and free the associated fuse_io_args while subsequent logic in the copy chain is still accessing them. An attacker with local access could potentially exploit this race to trigger a kernel panic. The fix involves ensuring lock_request() is called before replacing the page cache folio to prevent the arguments from being freed prematurely.
Affected products
- Linux Linux 2.6.35 to 6.9.x
Timeline
- 2026-07-19: disclosed
- 2026-07-19: advisory
References
- https://git.kernel.org/stable/c/0223f452532d9cd8a5e87c45de828fd93c99bd25
- https://git.kernel.org/stable/c/030fe3e9d8abdee303dd7e9e42f45082d382a407
- https://git.kernel.org/stable/c/46473ddccdc5065033e397d6e62c280dbcd3d9c2
- https://git.kernel.org/stable/c/5927b43a4f8d89e86930f524bf63e9c7e66f61b4
- https://git.kernel.org/stable/c/7c18691e0cfda29672f79bafde8abdb7710674f6
- https://git.kernel.org/stable/c/a078484921052d0badd827fcc2770b5cfc1d4120
- https://git.kernel.org/stable/c/af2892249d982a1c036ca456cc135374e68b6677