CVE-2026-53388

HIGH

fuse: re-lock request before replacing page cache folio

Title source: cna
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: fuse: re-lock request before replacing page cache folio fuse_try_move_folio() unlocks the request on entry but does not re-lock it on the success path. This means fuse_chan_abort() can end the request and free the fuse_io_args (eg fuse_readpages_end()) while the subsequent copy chain logic after fuse_try_move_folio() accesses the fuse_io_args, leading to use-after-free issues. Fix this by calling lock_request() before replace_page_cache_folio(). This ensures the request is locked on the success path which will prevent the fuse_io_args from being freed while the later copying logic runs, and also ensures that the ap->folios[i]->mapping is never null since ap->folios[i] will always point to the newfolio after replace_page_cache_folio().

Scores

CVSS v3 7.8
EPSS 0.0013
EPSS Percentile 3.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-416
Status published
Products (26)
linux/Kernel 2.6.35 - 5.15.211linux
linux/Kernel 5.16.0 - 6.1.177linux
linux/Kernel 6.13.0 - 6.18.37linux
linux/Kernel 6.19.0 - 7.0.14linux
linux/Kernel 6.2.0 - 6.6.144linux
linux/Kernel 6.7.0 - 6.12.95linux
linux/Kernel 7.1.0 - 7.1.2linux
Linux/Linux < 2.6.35
Linux/Linux 2.6.35
Linux/Linux 5.15.211 - 5.15.*
... and 16 more
Published Jul 19, 2026
Tracked Since Jul 19, 2026