PT-2026-26679 · Libfuse · Libfuse

·

CVE-2026-33179

·

Published

2026-03-20

·

Updated

2026-03-27

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libfuse versions 3.18.0 through 3.18.1
Description libfuse, the reference implementation of the Linux FUSE, contains a flaw in the fuse uring init queue function. A NULL pointer dereference and memory leak can occur when setting up the io uring queue, specifically when numa alloc local fails. This can lead to a local user crashing the FUSE daemon or causing resource exhaustion. The traditional /dev/fuse path is not affected; only the io uring transport is vulnerable.
Recommendations Update to version 3.18.2 or later.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33179
GHSA-X669-V3MQ-R358

Affected Products

Libfuse