« Volver al listado

CVE-2026-80857

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

fuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free

The abort_on_kill path in request_wait_answer() calls fuse_abort_conn() and returns without waiting for FR_FINISHED. If fuse_dev_do_write() is concurrently processing the same request (FR_LOCKED set), the caller frees req->args while it is still being accessed, causing a use-after-free.

Fix this by jumping to the existing wait_event(FR_FINISHED) instead of returning early. The wait will not hang because fuse_abort_conn() ensures all requests are ended.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80857",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "0c7fca880a40a209a9c92be14143996d14b93ff6",
              "lessThan": "a8bbb2a60513bf322170903c21462f0bf4f62be2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "204aa22a686bfee48daca7db620c1e017615f2ff",
              "lessThan": "715cb86e33cda43f5224cdc3fd5610c0b6a46f7a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "204aa22a686bfee48daca7db620c1e017615f2ff",
              "lessThan": "64b0b5cacbd2fea88001464cb712c9dfc795b26e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "300e812b882a174dca675d8028684001ad5826bc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.18.25",
              "lessThan": "6.18.50",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "7.0.2",
              "lessThan": "7.1",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "fs/fuse/dev.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.50",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.3",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/fuse/dev.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-04T16:18:14.810",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/64b0b5cacbd2fea88001464cb712c9dfc795b26e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/715cb86e33cda43f5224cdc3fd5610c0b6a46f7a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a8bbb2a60513bf322170903c21462f0bf4f62be2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free\n\nThe abort_on_kill path in request_wait_answer() calls fuse_abort_conn()\nand returns without waiting for FR_FINISHED.  If fuse_dev_do_write() is\nconcurrently processing the same request (FR_LOCKED set), the caller\nfrees req->args while it is still being accessed, causing a\nuse-after-free.\n\nFix this by jumping to the existing wait_event(FR_FINISHED) instead of\nreturning early.  The wait will not hang because fuse_abort_conn()\nensures all requests are ended."
    }
  ],
  "lastModified": "2026-09-07T16:17:30.437",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}