Junglewise Threat Intelligence

CVE-2026-64266: Linux Kernel FUSE use-after-free in fuse_ref_folio

CVE-2026-64266 · Severity: info · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's FUSE (Filesystem in Userspace) component, which allows non-privileged users to create their own file systems. A flaw in how the system handles memory locking during data transfers could lead to a 'use-after-free' condition. This could potentially allow an attacker to cause a system crash or execute unauthorized code, impacting the overall stability and security of the operating system.

Technical details

A use-after-free (UAF) vulnerability exists in fs/fuse/dev.c within the Linux kernel. The function fuse_ref_folio() (and its predecessor fuse_ref_page()) unlocks a request but fails to re-acquire the lock before returning to the caller. This creates a race condition where fuse_chan_abort() can terminate the request and trigger asynchronous cleanup callbacks, such as fuse_writepage_free(), which deallocate the request arguments. Subsequent logic in the copy chain then attempts to access these freed arguments. The fix involves ensuring the request is re-locked within fuse_ref_folio() before returning. This issue affects systems using FUSE with splice() support.

Affected products

  • Linux Linux Kernel 2.6.35 to 6.1.178, 6.6.x, 6.10.x

Timeline

  • 2026-07-24: patched: Fix committed to mainline and stable branches.
  • 2026-07-25: disclosed: CVE-2026-64266 published.

References

Related threats