Executive brief
A vulnerability was identified in the Linux kernel's FUSE (Filesystem in Userspace) component, which allows non-privileged users to create their own file systems. A flaw in how the system handles memory locking during data transfers could lead to a 'use-after-free' condition. This could potentially allow an attacker to cause a system crash or execute unauthorized code, impacting the overall stability and security of the operating system.
Technical details
A use-after-free (UAF) vulnerability exists in fs/fuse/dev.c within the Linux kernel. The function fuse_ref_folio() (and its predecessor fuse_ref_page()) unlocks a request but fails to re-acquire the lock before returning to the caller. This creates a race condition where fuse_chan_abort() can terminate the request and trigger asynchronous cleanup callbacks, such as fuse_writepage_free(), which deallocate the request arguments. Subsequent logic in the copy chain then attempts to access these freed arguments. The fix involves ensuring the request is re-locked within fuse_ref_folio() before returning. This issue affects systems using FUSE with splice() support.
Affected products
- Linux Linux Kernel 2.6.35 to 6.1.178, 6.6.x, 6.10.x
Timeline
- 2026-07-24: patched: Fix committed to mainline and stable branches.
- 2026-07-25: disclosed: CVE-2026-64266 published.
References
- https://git.kernel.org/stable/c/0e4a5a000123d81234e27a2f8187688cf608f755
- https://git.kernel.org/stable/c/1ca605cfa59377f0143fb35b5b01360f37d1b7c4
- https://git.kernel.org/stable/c/1f9156714592356b4fda57beac7eab9c2a462dd3
- https://git.kernel.org/stable/c/5630da218a45ba80f0aba0846cbe8aa655da122b
- https://git.kernel.org/stable/c/65a1c2551f7e16085acbb54aedde1feaa559ba7a
- https://git.kernel.org/stable/c/b5befa80fdbe287a98480effed9564712924add5
- https://git.kernel.org/stable/c/be353caffa8640f5e25fb3714ce8b0cef5e410e5