-
CVE-2026-80858
- EPSS 0.15%
- Veröffentlicht 04.09.2026 15:55:12
- Zuletzt bearbeitet 11.09.2026 10:16:51
- Erkennungen
fuse: publish io-uring queues with release semantics
In the Linux kernel, the following vulnerability has been resolved: fuse: publish io-uring queues with release semantics fuse_uring_create_queue() initializes a fuse_ring_queue and then publishes the pointer into ring->queues[qid] with WRITE_ONCE() under the fch->lock. There are several readers that may concurrently be fetching that pointer locklessly and then deferencing it. WRITE_ONCE() doesn't ensure ordering of the queue's field initialization before the ring->queues[qid] pointer assignment. The queue must be published with smp_store_release() so the field initialization is guaranteed to happen before. Readers in paths where the read may happen concurrently with the store need to use READ_ONCE() because any race involving a plain access is undefined.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
24fe962c86f55347385933a1b06ca71b60854690
Version <
a5bb215dbc34b4c6a5e144ea1416bf66450d519f
Status
affected
Version
24fe962c86f55347385933a1b06ca71b60854690
Version <
a1bb359c443d048fe5dfd6ca9caf4e3897f3e9aa
Status
affected
Version
24fe962c86f55347385933a1b06ca71b60854690
Version <
42df916e5a5f8fb4b60c8cefb54318d1ec02c580
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.14
Status
affected
Version
0
Version <
6.14
Status
unaffected
Version <=
6.18.*
Version
6.18.51
Status
unaffected
Version <=
7.2.*
Version
7.2.3
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.041 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/a1bb359c443d048fe5dfd6ca9caf4e3897f3e9aa
https://git.kernel.org/stable/c/42df916e5a5f8fb4b60c8cefb54318d1ec02c580
https://git.kernel.org/stable/c/a5bb215dbc34b4c6a5e144ea1416bf66450d519f