Opened 7 months ago
Closed 6 months ago
#23008 closed enhancement (fixed)
fuse3-3.18.2
| Reported by: | Bruce Dubbs | Owned by: | zeckma |
|---|---|---|---|
| Priority: | high | Milestone: | 13.1 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version.
Change History (6)
comment:1 by , 6 months ago
| Priority: | normal → high |
|---|
comment:2 by , 6 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:3 by , 6 months ago
libfuse 3.18.2 (2026-03-18) =========================== * Fix two io-uring issues that might be security critical * fuse-io-uring: Fix UAF and NULL deref in startup error path * fuse-io-uring: Fix NULL deref and memory leak in fuse_uring_init_queue
Fixed at aed0ffb573.
Leaving open for SA.
comment:5 by , 6 months ago
| Status: | new → assigned |
|---|
Note:
See TracTickets
for help on using tickets.

Two memory safety vulnerabilities in libfuse's io_uring code path (introduced in 3.18.0) have been fixed in libfuse 3.18.2. Only the io_uring transport is affected; the traditional /dev/fuse path is not.
Affected versions: libfuse >= 3.18.0, < 3.18.2 Fixed in: libfuse 3.18.2
CVE-2026-33150: Use-After-Free Severity: High (CVSS 7.8) CWE: CWE-416
Use-after-free in io_uring session shutdown path. A local user can crash the FUSE daemon or potentially execute arbitrary code.
Advisory: https://github.com/libfuse/libfuse/security/advisories/GHSA-qxv7-xrc2-qmfx Fix: https://github.com/libfuse/libfuse/commit/49fcd891a58f622c098e2ca67d66086f7b213836 Credit: Abhinav Agarwal (reporter)
Remediation review: Akshat Sinha
CVE-2026-33179: NULL Pointer Dereference + Memory Leak Severity: Moderate (CVSS 5.5) CWE: CWE-476
Missing NULL checks and error-path cleanup in io_uring queue initialization can crash the FUSE daemon on allocation failure and leak NUMA memory.
Advisory: https://github.com/libfuse/libfuse/security/advisories/GHSA-x669-v3mq-r358 Fix: https://github.com/libfuse/libfuse/commit/7beb86c09b6ec5aab14dc25256ed8a5ad18554d7 Credit: Abhinav Agarwal (reporter) Remediation review: Akshat Sinha
Both issues were reported privately to the libfuse maintainer and fixed in a coordinated release.
Timeline: