CVE-2026-64263

Source
https://cve.org/CVERecord?id=CVE-2026-64263
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64263.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64263
Downstream
Related
Published
2026-07-25T08:49:13.217Z
Modified
2026-08-18T03:31:27.968777869Z
Summary
fuse-uring: fix moving cancelled entry to ent_in_userspace list
Details

In the Linux kernel, the following vulnerability has been resolved:

fuse-uring: fix moving cancelled entry to entinuserspace list

fuseuringcancel() moves entries that are available (these have no reqs attached) to the entinuserspace list. entlistrequestexpired() checks the first entry on entinuserspace and dereferences ent->fusereq unconditionally, which will crash on a cancelled entry that was moved to this list.

Fix this by freeing the entry and dropping queuerefs directly in fuseuringcancel(). This is safe because cancel is the cancel handler itself - after iouringcmddone(), no more cancels will be dispatched for this command, and teardown serializes with cancel via queue->lock.

Since cancel now decrements queuerefs, fuseuringabort() must no longer gate fuseuringabortendrequests() on queuerefs > 0, as cancelled entries may have already dropped queue_refs while requests are still queued. Remove the gate so abort always flushes requests and stops queues.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64263.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4fea593e625cd50d4d11be227007849b12f17bfb
Fixed
50f3e03db823cabc41fe35c27d77c2bdb112baad
Fixed
e8afc85acdf329361b2d8df2ad9b52364686235f
Fixed
198f45eeb9f78b2a2d6d8be95e4e43468eb2c6bc

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64263.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.16.0
Fixed
6.18.39
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64263.json"