CVE-2026-53388

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
19/07/2026
Last modified:
29/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> fuse: re-lock request before replacing page cache folio<br /> <br /> fuse_try_move_folio() unlocks the request on entry but does not<br /> re-lock it on the success path. This means fuse_chan_abort() can end the<br /> request and free the fuse_io_args (eg fuse_readpages_end()) while the<br /> subsequent copy chain logic after fuse_try_move_folio() accesses the<br /> fuse_io_args, leading to use-after-free issues.<br /> <br /> Fix this by calling lock_request() before replace_page_cache_folio().<br /> This ensures the request is locked on the success path which will<br /> prevent the fuse_io_args from being freed while the later copying logic<br /> runs, and also ensures that the ap-&gt;folios[i]-&gt;mapping is never null<br /> since ap-&gt;folios[i] will always point to the newfolio after<br /> replace_page_cache_folio().

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 2.6.35 (including) 5.15.211 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 6.1.177 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.144 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.12.95 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.18.37 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (including) 7.0.14 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 7.1 (including) 7.1.2 (excluding)