Review reviewHigh

CVE-2026-53388

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: fuse: re-lock request before replacing page cache folio fuse_try_move_folio() unlocks the request on entry but does not re-lock it on the success path. This means fuse_chan_abort() can end the request and free the fuse_io_args (eg fuse_readpages_end()) while the subsequent copy chain logic after fuse_try_move_folio() accesses the fuse_io_args, leading to use-after-free issues. Fix this by calling lock_request() before replace_page_cache_folio(). This ensures the request is locked on the success path which will prevent the f...

CVSS
7.8
EPSS
0.13%
3.20% percentile
CISA KEV
Not listed
Published
2026.07.19
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.13%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: fuse: re-lock request before replacing page cache folio fuse_try_move_folio() unlocks the request on entry but does not re-lock it on the success path. This means fuse_chan_abort() can end the request and free the fuse_io_args (eg fuse_readpages_end()) while the subsequent copy chain logic after fuse_try_move_folio() accesses the fuse_io_args, leading to use-after-free issues. Fix this by calling lock_request() before replace_page_cache_folio(). This ensures the request is locked on the success path which will prevent the f...

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= ce534fb052928ce556639d7ecf01cbf4e01321e1 < 7c18691e0cfda29672f79bafde8abdb7710674f6, >= ce534fb052928ce556639d7ecf01cbf4e01321e1 < 5927b43a4f8d89e86930f524bf63e9c7e66f61b4, >= ce534fb052928ce556639d7ecf01cbf4e01321e1 < 030fe3e9d8abdee303dd7e9e42f45082d382a407, >= ce534fb052928ce556639d7ecf01cbf4e01321e1 < 46473ddccdc5065033e397d6e62c280dbcd3d9c2, >= ce534fb052928ce556639d7ecf01cbf4e01321e1 < af2892249d982a1c036ca456cc135374e68b6677, >= ce534fb052928ce556639d7ecf01cbf4e01321e1 < 0223f452532d9cd8a5e87c45de828fd93c99bd25, >= ce534fb052928ce556639d7ecf01cbf4e01321e1 < e28db6ac4792d065ab32565fd9f0a2361c3d4666, >= ce534fb052928ce556639d7ecf01cbf4e01321e1 < a078484921052d0badd827fcc2770b5cfc1d4120, >= 2.6.35, >= 2.6.35 < 5.15.211, >= 5.16 < 6.1.177, >= 6.2 < 6.6.144, >= 6.7 < 6.12.95, >= 6.13 < 6.18.37, >= 6.19 < 7.0.14, >= 7.1 < 7.1.2
Fixed versions
5.15.211, 6.1.177, 6.6.144, 6.12.95, 6.18.37, 7.0.14, 7.1.2

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416