Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-49p8-h7pf-grwp

Опубликовано: 25 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

In the Linux kernel, the following vulnerability has been resolved:

fuse-uring: Avoid use-after-free in fuse_uring_async_stop_queues

fuse_uring_async_stop_queues() might run when the last reference on ring->queue_refs was already dropped.

In order to avoid an early destruction a reference on struct fuse_conn is now taken before starting fuse_uring_async_stop_queues() and that reference is only released when that delayed work queue terminates.

In the Linux kernel, the following vulnerability has been resolved:

fuse-uring: Avoid use-after-free in fuse_uring_async_stop_queues

fuse_uring_async_stop_queues() might run when the last reference on ring->queue_refs was already dropped.

In order to avoid an early destruction a reference on struct fuse_conn is now taken before starting fuse_uring_async_stop_queues() and that reference is only released when that delayed work queue terminates.

EPSS

Процентиль: 5%
0.00157
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
8 дней назад

In the Linux kernel, the following vulnerability has been resolved: fuse-uring: Avoid use-after-free in fuse_uring_async_stop_queues fuse_uring_async_stop_queues() might run when the last reference on ring->queue_refs was already dropped. In order to avoid an early destruction a reference on struct fuse_conn is now taken before starting fuse_uring_async_stop_queues() and that reference is only released when that delayed work queue terminates.

redhat
8 дней назад

A flaw was found in the Linux kernel's `fuse-uring` component. This use-after-free vulnerability allows a local attacker to potentially achieve privilege escalation. The issue arises when the `fuse_uring_async_stop_queues()` function attempts to access memory that has already been freed, leading to unpredictable system behavior or unauthorized access. This flaw is mitigated by ensuring that a proper reference to the `fuse_conn` structure is maintained until the associated work queue has fully terminated.

CVSS3: 7.8
nvd
8 дней назад

In the Linux kernel, the following vulnerability has been resolved: fuse-uring: Avoid use-after-free in fuse_uring_async_stop_queues fuse_uring_async_stop_queues() might run when the last reference on ring->queue_refs was already dropped. In order to avoid an early destruction a reference on struct fuse_conn is now taken before starting fuse_uring_async_stop_queues() and that reference is only released when that delayed work queue terminates.

CVSS3: 7.8
debian
8 дней назад

In the Linux kernel, the following vulnerability has been resolved: f ...

EPSS

Процентиль: 5%
0.00157
Низкий

7.8 High

CVSS3