CVE-2026-53381
Severity CVSS v4.0:
Pending analysis
Type:
CWE-416
Use After Free
Publication date:
19/07/2026
Last modified:
29/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
virtiofs: fix UAF on submount umount<br />
<br />
iput() called from fuse_release_end() can Oops if the super block has<br />
already been destroyed. Normally this is prevented by waiting for<br />
num_waiting to go down to zero before commencing with super block shutdown.<br />
<br />
This only works, however, for the last submount instance, as the wait<br />
counter is per connection, not per superblock.<br />
<br />
Revert to using synchronous release requests for the auto_submounts case,<br />
which is virtiofs only at this time.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.10.246 (including) | 5.10.260 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.15.196 (including) | 5.15.211 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.1.158 (including) | 6.1.177 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.6.115 (including) | 6.6.144 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.12.54 (including) | 6.12.95 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.17.4 (including) | 6.18.37 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 7.0.14 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 7.1 (including) | 7.1.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/06b41351779e9289e8785694ade9042ae85e41ea
- https://git.kernel.org/stable/c/0b809199ff87c44487e516a725dd4be2185712ce
- https://git.kernel.org/stable/c/1cc0e3a0c6499aaaa2f21a4fcbba388486afb25e
- https://git.kernel.org/stable/c/2181a09ba980f142650fb053666350ead4471cfe
- https://git.kernel.org/stable/c/2abfd3ffbd9452f72535d96ff3982b3ab1f8f2f9
- https://git.kernel.org/stable/c/39a2b95e008665c14f84e50ed411d898df7cd11b
- https://git.kernel.org/stable/c/607a1d4c42f649e6197567c0448fd9ebb316cd42
- https://git.kernel.org/stable/c/97c4691653d145dcc699eca5d3aba3219a520f1f
- https://git.kernel.org/stable/c/e09412a714bcd49375198427bb4aa005037a9d6f



