PT-2026-64483 · Linux+1 · Linux Kernel+1
CVE-2026-64262
·
Published
2026-07-25
·
Updated
2026-09-07
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the fuse-uring component where the
fuse uring send in task() function fails to properly discharge the ring entry's reference to the fuse req when io uring delivers task work with tw.cancel set. This occurs during specific conditions such as PF EXITING, PF KTHREAD fallback, or percpu ref is dying on the ring context. Consequently, the fuse req remains linked and fuse request end() is never called, causing the originating syscall thread to block in D-state within request wait answer(). For FR BACKGROUND requests, the fc->num background counter is not decremented, which can lead to a stall of all subsequent background operations once max background is reached. Additionally, routing the entry through fuse uring send() can leave a request-less entry in ent in userspace, leading to a NULL-dereference in the ent list request expired() function.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Ubuntu