Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33150

Опубликовано: 20 мар. 2026
Источник: redhat
CVSS3: 7.8

Описание

libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a use-after-free vulnerability in the io_uring subsystem of libfuse allows a local attacker to crash FUSE filesystem processes and potentially execute arbitrary code. When io_uring thread creation fails due to resource exhaustion (e.g., cgroup pids.max), fuse_uring_start() frees the ring pool structure but stores the dangling pointer in the session state, leading to a use-after-free when the session shuts down. The trigger is reliable in containerized environments where cgroup pids.max limits naturally constrain thread creation. This issue has been patched in version 3.18.2.

A flaw was found in libfuse. A use-after-free vulnerability in the io_uring subsystem allows a local attacker to potentially execute arbitrary code and crash FUSE (Filesystem in Userspace) filesystem processes. This occurs when io_uring thread creation fails due to resource exhaustion, such as limits imposed by cgroup pids.max, causing a dangling pointer to be stored and later used during session shutdown. This vulnerability is reliably triggered in containerized environments.

Отчет

An Important use-after-free vulnerability in libfuse's io_uring subsystem can lead to arbitrary code execution or denial of service for local attackers. This flaw is reliably triggered in containerized environments when io_uring thread creation fails due to resource exhaustion, such as cgroup pids.max limits. Red Hat Enterprise Linux 7 is not affected. Red Hat Enterprise Linux 8.10 and Fedora are affected when using fuse-sshfs.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7fuseNot affected
Red Hat Enterprise Linux 8fuse-sshfsAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2449771libfuse: libfuse: Arbitrary code execution via use-after-free in io_uring subsystem

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
5 месяцев назад

libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a use-after-free vulnerability in the io_uring subsystem of libfuse allows a local attacker to crash FUSE filesystem processes and potentially execute arbitrary code. When io_uring thread creation fails due to resource exhaustion (e.g., cgroup pids.max), fuse_uring_start() frees the ring pool structure but stores the dangling pointer in the session state, leading to a use-after-free when the session shuts down. The trigger is reliable in containerized environments where cgroup pids.max limits naturally constrain thread creation. This issue has been patched in version 3.18.2.

CVSS3: 7.8
nvd
5 месяцев назад

libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a use-after-free vulnerability in the io_uring subsystem of libfuse allows a local attacker to crash FUSE filesystem processes and potentially execute arbitrary code. When io_uring thread creation fails due to resource exhaustion (e.g., cgroup pids.max), fuse_uring_start() frees the ring pool structure but stores the dangling pointer in the session state, leading to a use-after-free when the session shuts down. The trigger is reliable in containerized environments where cgroup pids.max limits naturally constrain thread creation. This issue has been patched in version 3.18.2.

CVSS3: 7.8
debian
5 месяцев назад

libfuse is the reference implementation of the Linux FUSE. From versio ...

CVSS3: 7.8
fstec
5 месяцев назад

Уязвимость функции fuse_uring_start() библиотеки для создания и использования виртуальных файловых систем libfuse, позволяющая нарушителю выполнить произвольный код

7.8 High

CVSS3