SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-64264

MEDIUM · CVSS 5.5 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-07-25 · Last synced 2026-08-24

CyberRota Analysis

AI-Generated

The vulnerability in the Linux kernel affects the fuse-uring subsystem, where improper error handling in the `fuse_uring_commit` function can lead to the overwriting of error codes with positive residual values. This flaw may cause FUSE callers to mistakenly interpret a failure as a success, potentially leading to the use of uninitialized or partially filled request arguments. Organizations utilizing Linux systems with FUSE implementations should prioritize addressing this vulnerability to prevent exploitation and ensure the integrity of their file operations.

CVE
CVE-2026-64264
Severity
MEDIUM
CVSS
5.5
EPSS
0.15%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: fuse-uring: fix EFAULT clobber in fuse_uring_commit copy_from_user() returns the number of bytes not copied as an unsigned residual on failure (1..sizeof(struct fuse_out_header)). fuse_uring_commit stores that residual in ssize_t err, sets req->out.h.error to -EFAULT, then jumps to out: with err still holding the positive residual. err = copy_from_user(&req->out.h, &ent->headers->in_out, sizeof(req->out.h)); if (err) { req->out.h.error = -EFAULT; goto out; /* err is the positive residual */ } ... out: fuse_uring_req_end(ent, req, err); fuse_uring_req_end() then runs if (error) req->out.h.error = error; which overwrites the just-assigned -EFAULT with the positive residual. FUSE callers such as fuse_simple_request() test err < 0 to detect failure, so the positive value is interpreted as success and the caller proceeds with an uninitialised or partial req->out.args. Fix by assigning err = -EFAULT in the failure branch before jumping to out, so fuse_uring_req_end() receives a negative errno and sets req->out.h.error to -EFAULT.

Related CVEs

Other vulnerabilities affecting the same vendor(s)