In the Linux kernel, the following vulnerability has been resolved:
virtiofs: fix UAF on submount umount
iput() called from fuse_release_end() can Oops if the super block has
already been destroyed. Normally this is prevented by waiting for
num_waiting to go down to zero before commencing with super block shutdown.
This only works, however, for the last submount instance, as the wait
counter is per connection, not per superblock.
Revert to using synchronous release requests for the auto_submounts case,
which is virtiofs only at this time.
References
Configurations
Configuration 1 (hide)
|
History
29 Jul 2026, 16:19
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | |
| References | () https://git.kernel.org/stable/c/06b41351779e9289e8785694ade9042ae85e41ea - Patch | |
| References | () https://git.kernel.org/stable/c/0b809199ff87c44487e516a725dd4be2185712ce - Patch | |
| References | () https://git.kernel.org/stable/c/1cc0e3a0c6499aaaa2f21a4fcbba388486afb25e - Patch | |
| References | () https://git.kernel.org/stable/c/2181a09ba980f142650fb053666350ead4471cfe - Patch | |
| References | () https://git.kernel.org/stable/c/2abfd3ffbd9452f72535d96ff3982b3ab1f8f2f9 - Patch | |
| References | () https://git.kernel.org/stable/c/39a2b95e008665c14f84e50ed411d898df7cd11b - Patch | |
| References | () https://git.kernel.org/stable/c/607a1d4c42f649e6197567c0448fd9ebb316cd42 - Patch | |
| References | () https://git.kernel.org/stable/c/97c4691653d145dcc699eca5d3aba3219a520f1f - Patch | |
| References | () https://git.kernel.org/stable/c/e09412a714bcd49375198427bb4aa005037a9d6f - Patch | |
| CWE | CWE-416 | |
| First Time |
Linux linux Kernel
Linux |
20 Jul 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
19 Jul 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-19 12:16
Updated : 2026-07-29 16:19
NVD link : CVE-2026-53381
Mitre link : CVE-2026-53381
CVE.ORG link : CVE-2026-53381
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-416
Use After Free
