Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-90704.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-90704
Upstream
Published
2026-06-25T09:16:34Z
Modified
2026-08-28T17:47:38.693793028Z
Summary
CVE-2026-53168 affecting package kernel for versions less than 6.6.143.1-1
Details

In the Linux kernel, the following vulnerability has been resolved:

fuse: reject fuse_notify() pagecache ops on directories

The operations FUSENOTIFYSTORE and FUSENOTIFYRETRIEVE allow the FUSE daemon to actively write/read pagecache contents.

For directories with FOPENCACHEDIR, the pagecache is used as kernel-internal cache storage, and userspace is not supposed to have direct access to this cache - in particular, fuseparsecache() will hit WARN_ON() if the cache contains bogus data.

Reject FUSENOTIFYSTORE and FUSENOTIFYRETRIEVE on anything other than regular files with -EINVAL.

References

Affected packages

Azure Linux:3 / kernel

Package

Name
kernel
Purl
pkg:rpm/azure-linux/kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.6.143.1-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-90704.json"