Executive brief
A vulnerability in the Linux kernel's FUSE (Filesystem in Userspace) subsystem can cause system processes to hang indefinitely. When certain background tasks are cancelled, the system fails to properly clean up internal requests, leading to a resource leak. Over time, this can exhaust the system's ability to process new filesystem requests, effectively causing a denial of service for applications relying on FUSE-based storage.
Technical details
A vulnerability exists in the fuse-uring implementation within the Linux kernel (specifically in fs/fuse/dev_uring.c). When io_uring delivers task work with the cancel flag set (e.g., during task exit or ring context dying), the function fuse_uring_send_in_task() fails to properly discharge the reference to fuse_req. This causes the request to remain linked in the processing queue, leaving the originating syscall thread blocked in a D-state (uninterruptible sleep). Additionally, background request counters are not decremented, eventually hitting max_background limits and stalling all subsequent FUSE operations. A secondary risk of a NULL pointer dereference exists if the request is ended without properly removing the entry from the userspace queue. The fix ensures that cancelled entries are directly released, the io_uring command is completed, and the fuse_req is properly terminated.
Affected products
- Linux Linux Kernel c2c9af9a0b13 to bb476ef8e1027a9d509fbaaf81f5061a07e9e5a7
Timeline
- 2026-06-08: other: Patch authored
- 2026-07-25: disclosed: CVE published