CVE-2026-64260

Source
https://cve.org/CVERecord?id=CVE-2026-64260
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64260.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64260
Downstream
Published
2026-07-25T08:49:11.395Z
Modified
2026-07-28T04:03:02.585066859Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
fuse-uring: Avoid queue->stopped races and set/read that value under lock
Details

In the Linux kernel, the following vulnerability has been resolved:

fuse-uring: Avoid queue->stopped races and set/read that value under lock

There are several readers of queue->stopped that check the value under lock, but fuseuringcommitfetch() did not and actually the value was not set under the lock in fuseuringabortendrequests() either. Especially in fuseuringcommitfetch it is important to check under a lock, because due to races 'struct fusereq' might be freed with fuserequest_end, but another thread/cpu might already do teardown work.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64260.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4a9bfb9b6850fec0685447aed280533cf980de70
Fixed
39c8e925b207afceffaa5382416ed405e0223a03
Fixed
4021a3a79eee551d95fe1e1e7c1b195d34ba8c08
Fixed
b70a3aca16934c196f92abb17b01c1647b9bb63c

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64260.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.14.0
Fixed
6.18.39
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64260.json"