CVE-2026-64258 PUBLISHED

fuse-uring: remove request-less entries from ent_w_req_queue to fix NULL deref

Assigner: Linux
Reserved: 19.07.2026 Published: 25.07.2026 Updated: 25.07.2026

In the Linux kernel, the following vulnerability has been resolved:

fuse-uring: remove request-less entries from ent_w_req_queue to fix NULL deref

If a copy into the userspace ring buffer fails, a request will be terminated and fuse_uring_req_end() will set ent->fuse_req to NULL but it will leave the entry on ent_w_req_queue in FRRS_FUSE_REQ state. This can lead to a NULL deref if the request expiration logic scans ent_w_req_queue in the window before the entry is moved off it.

Fix this by taking the entry off ent_w_req_queue and changing its state from FRRS_FUSE_REQ to FRRS_INVALID before terminating the request.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 4fea593e625cd50d4d11be227007849b12f17bfb to 0b466cf1b96e191b06b496c4de79da15315c3a9a (excl.)
  • affected from 4fea593e625cd50d4d11be227007849b12f17bfb to 0a7f33010c0e4cd92937e088a54350381fd0fbf2 (excl.)
  • affected from 4fea593e625cd50d4d11be227007849b12f17bfb to 1c57a69be962d459c5e705f5cb4355b841b3461c (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.16 is affected
  • unaffected from 0 to 6.16 (excl.)
  • unaffected from 6.18.39 to 6.18.* (incl.)
  • unaffected from 7.1.4 to 7.1.* (incl.)
  • unaffected from 7.2-rc1 to * (incl.)

References