fuse: fix livelock in synchronous file put from fuseblk workers
In the Linux kernel, the following vulnerability has been resolved: fuse: fix livelock in synchronous file put from fuseblk workers I observed a hang when running generic/323 against a fuseblk server. This test opens a file, initiates a lot of AIO writes to that file descriptor, and closes the file descriptor before the writes complete. Unsurprisingly, the AIO exerciser threads are mostly stuck waiting for responses from the fuseblk server: # cat /proc/372265/task/372313/stack [<0>] request_wait_answer+0x1fe/0x2a0 [fuse] [<0>] __fuse_simple_request+0xd3/0x2b0 [fuse] [<0>] fuse_do_getattr+0xfc/0x1f0 [fuse] [<0>] fuse_file_read_iter+0xbe/0x1c0 [fuse] [<0>] aio_read+0x130/0x1e0 [<0>] io_submit_one+0x542/0x860 [<0>] __x64_sys_io_submit+0x98/0x1a0 [<0>] do_syscall_64+0x37/0xf0 [<0>] entry_SYSCALL_64_after_hwframe+0x4b/0x53 But the /weird/ part is that the fuseblk server threads are waiting for responses from itself: # cat /proc/372210/task/372232/stack [<0>] request_wait_answer+0x1fe/0x2a0 [fuse] [<0>] __fuse_simple_request+0xd3/0x2b0 [fuse] [<0>] fuse_file_put+0x9a/0xd0 [fuse] [<0>] fuse_release+0x36/0x50 [fuse] [<0>] __fput+0xec/0x2b0 [<0>] task_work_run+0x55/0x90 [<0>] syscall_exit_to_user_mode+0xe9/0x100 [<0>] do_syscall_64+0x43/0xf0 [<0>] entry_SYSCALL_64_after_hwframe+0x4b/0x53 The fuseblk server is fuse2fs so there's nothing all that exciting in the server itself. So why is the fuse server calling fuse_file_put? The commit message for the fstest sheds some light on that: "By closing the file descriptor before calling io_destroy, you pretty much guarantee that the last put on the ioctx will be done in interrupt context (during I/O completion). Aha. AIO fgets a new struct file from the fd when it queues the ioctx. The completion of the FUSE_WRITE command from userspace causes the fuse server to call the AIO completion function. The completion puts the struct file, queuing a delayed fput to the fuse server task. When the fuse server task returns to userspace, it has to run the delayed fput, which in the case of a fuseblk server, it does synchronously. Sending the FUSE_RELEASE command sychronously from fuse server threads is a bad idea because a client program can initiate enough simultaneous AIOs such that all the fuse server threads end up in delayed_fput, and now there aren't any threads left to handle the queued fuse commands. Fix this by only using asynchronous fputs when closing files, and leave a comment explaining why.
- Yayın
- 4 Ara 2025
- Güncelleme
- 17 Haz 2026
- EPSS
- %0,2 · 8. yüzdelik
- CWE
- —
Takip etmek için giriş yap · Takip ettiğin kayıt KEV’e girer, istismarı çıkar ya da güncellenirse bildirim alırsın.
Rapor araçları
Aksiyon skoru
0
İzleyin
Şimdilik düşük öncelik.
- CVSS
- 0 / 40 · —
- CISA KEV
- 0 / 30 · Listede değil
- EPSS
- 0 / 30 · %0,2
Noroxi analizi
Bu kayıt için henüz Noroxi analizi yok
Veritabanındaki yüz binlerce zafiyetin tamamına elle analiz yazmıyoruz; bu dürüst olmazdı. Öne çıkan ve sahada etkisi olan zafiyetler için mekanizma, tespit ve kapatma adımlarını ekibimiz yazıyor.
Bu ürünü kullanıyoruz, yardım isteyinEtkilenen sistemler
—
Üreticinin bildirdiği sürümler
Kaydı açan otorite (Linux) tarafından bildirilen etkilenen sürüm aralıkları. NVD'nin CPE analizinden bağımsızdır ve genellikle ondan önce gelir.
Linux Linux
- 9efe56738fecd591b5bf366a325440f9b457ebd6, 5c46eb076e0a1b2c1769287cd6942e4594ade1b1, 83e6726210d6c815ce044437106c738eda5ff6f6, 23d154c71721fd0fa6199851078f32e6bd765664, ca3edc920f5fd7d8ac040caaf109f925c24620a0, 2.6.38etkilenir
- 5a18ec176c934ca1bc9dc61580a5e0e90a9b5733 ve sonrası · 548e1f2bac1d4df91a6138f26bb4ab00323fd948 öncesietkilenir · git
- 5a18ec176c934ca1bc9dc61580a5e0e90a9b5733 ve sonrası · cfd1aa3e2b71f3327cb373c45a897c9028c62b35 öncesietkilenir · git
- 5a18ec176c934ca1bc9dc61580a5e0e90a9b5733 ve sonrası · 83b375c6efef69b1066ad2d79601221e7892745a öncesietkilenir · git
- 5a18ec176c934ca1bc9dc61580a5e0e90a9b5733 ve sonrası · bfd17b6138df0122a95989457d8e18ce0b86165e öncesietkilenir · git
- 5a18ec176c934ca1bc9dc61580a5e0e90a9b5733 ve sonrası · b26923512dbe57ae4917bafd31396d22a9d1691a öncesietkilenir · git
- 5a18ec176c934ca1bc9dc61580a5e0e90a9b5733 ve sonrası · f19a1390af448d9e193c08e28ea5f727bf3c3049 öncesietkilenir · git
- 5a18ec176c934ca1bc9dc61580a5e0e90a9b5733 ve sonrası · 26e5c67deb2e1f42a951f022fdf5b9f7eb747b01 öncesietkilenir · git
- 2.6.32.32 ve sonrası · 2.6.33 öncesietkilenir · semver
- 2.6.33.8 ve sonrası · 2.6.34 öncesietkilenir · semver
Paket düzeyi etkilenme
OSV ve GitHub Advisory verisi: ekosistem, paket ve aralık. SBOM eşleşmesi bu tabloyu kullanır.
| Ekosistem | Paket | Etkilenen aralık | Düzeltme |
|---|---|---|---|
| Debian:12 | linux | 6.1.158-1 öncesi | 6.1.158-1 |
| Debian:13 | linux | 6.12.57-1 öncesi | 6.12.57-1 |
| Debian:14 | linux | 6.17.6-1 öncesi | 6.17.6-1 |
| openSUSE:Leap 16.0 | dtb-aarch64 | 6.12.0-160000.9.1 öncesi | 6.12.0-160000.9.1 |
| openSUSE:Leap 16.0 | kernel-64kb | 6.12.0-160000.9.1 öncesi | 6.12.0-160000.9.1 |
| openSUSE:Leap 16.0 | kernel-azure | 6.12.0-160000.9.1 öncesi | 6.12.0-160000.9.1 |
| openSUSE:Leap 16.0 | kernel-default | 6.12.0-160000.9.1 öncesi | 6.12.0-160000.9.1 |
| openSUSE:Leap 16.0 | kernel-default-base | 6.12.0-160000.9.1.160000.2.6 öncesi | 6.12.0-160000.9.1.160000.2.6 |
| openSUSE:Leap 16.0 | kernel-docs | 6.12.0-160000.9.1 öncesi | 6.12.0-160000.9.1 |
| openSUSE:Leap 16.0 | kernel-kvmsmall | 6.12.0-160000.9.1 öncesi | 6.12.0-160000.9.1 |
| openSUSE:Leap 16.0 | kernel-obs-build | 6.12.0-160000.9.1 öncesi | 6.12.0-160000.9.1 |
| openSUSE:Leap 16.0 | kernel-obs-qa | 6.12.0-160000.9.1 öncesi | 6.12.0-160000.9.1 |
| openSUSE:Leap 16.0 | kernel-rt | 6.12.0-160000.9.1 öncesi | 6.12.0-160000.9.1 |
| openSUSE:Leap 16.0 | kernel-source | 6.12.0-160000.9.1 öncesi | 6.12.0-160000.9.1 |
| openSUSE:Leap 16.0 | kernel-syms | 6.12.0-160000.9.1 öncesi | 6.12.0-160000.9.1 |
| openSUSE:Leap 16.0 | kernel-zfcpdump | 6.12.0-160000.9.1 öncesi | 6.12.0-160000.9.1 |
| SUSE:Linux Enterprise Live Patching 12 SP5 | kernel-default | 4.12.14-122.296.1 öncesi | 4.12.14-122.296.1 |
| SUSE:Linux Enterprise Live Patching 12 SP5 | kgraft-patch-SLE12-SP5_Update_78 | 1-8.3.1 öncesi | 1-8.3.1 |
| SUSE:Linux Enterprise Server 12 SP5-LTSS | kernel-source | 4.12.14-122.296.1 öncesi | 4.12.14-122.296.1 |
| SUSE:Linux Enterprise Server 12 SP5-LTSS | kernel-syms | 4.12.14-122.296.1 öncesi | 4.12.14-122.296.1 |
| SUSE:Linux Enterprise Server 16.0 | kernel-azure | 6.12.0-160000.9.1 öncesi | 6.12.0-160000.9.1 |
| SUSE:Linux Enterprise Server 16.0 | kernel-docs | 6.12.0-160000.9.1 öncesi | 6.12.0-160000.9.1 |
| SUSE:Linux Enterprise Server 16.0 | kernel-kvmsmall | 6.12.0-160000.9.1 öncesi | 6.12.0-160000.9.1 |
| SUSE:Linux Enterprise Server 16.0 | kernel-obs-qa | 6.12.0-160000.9.1 öncesi | 6.12.0-160000.9.1 |
+8
Aynı üründe
linux: tüm kayıtlarAynı birincil ürünün en yüksek skorlu diğer kayıtları.
- CVE-2026-74705udp: fix potential use-after-free in tunnel segmentation40Planlayın
- CVE-2026-74612veth: fix skb length accounting after XDP frag adjustment40Planlayın
- CVE-2026-74475vxlan: use neigh_ha_snapshot() in route_shortcircuit()40Planlayın
- CVE-2026-74309vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler40Planlayın
- CVE-2026-74280crypto: marvell/octeontx - fix DMA cleanup using wrong loop index40Planlayın
- CVE-2026-74279crypto: cavium/cpt - fix DMA cleanup using wrong loop index40Planlayın
Düzeltme
Hangi sürüme geçmeli
Üretici, paket deposu ve Microsoft kayıtlarından derlenen düzeltme sürümleri. Yükseltmeden önce üreticinin notunu doğrulayın.
| Ürün / paket | Düzeltilmiş sürüm | Kaynak |
|---|---|---|
| Linux Linux | 2.6.33 | Üretici (CNA) |
| Linux Linux | 2.6.34 | Üretici (CNA) |
| Linux Linux | 2.6.35 | Üretici (CNA) |
| Linux Linux | 2.6.36 | Üretici (CNA) |
| Linux Linux | 2.6.38 | Üretici (CNA) |
| Linux Linux | 26e5c67deb2e1f42a951f022fdf5b9f7eb747b01 | Üretici (CNA) |
| Linux Linux | 548e1f2bac1d4df91a6138f26bb4ab00323fd948 | Üretici (CNA) |
| Linux Linux | 83b375c6efef69b1066ad2d79601221e7892745a | Üretici (CNA) |
| Linux Linux | b26923512dbe57ae4917bafd31396d22a9d1691a | Üretici (CNA) |
| Linux Linux | bfd17b6138df0122a95989457d8e18ce0b86165e | Üretici (CNA) |
| Linux Linux | cfd1aa3e2b71f3327cb373c45a897c9028c62b35 | Üretici (CNA) |
| Linux Linux | f19a1390af448d9e193c08e28ea5f727bf3c3049 | Üretici (CNA) |
| debian:linux | 6.1.158-1 · Debian:12 | Paket deposu (OSV) |
| opensuse:dtb-aarch64 | 6.12.0-160000.9.1 · openSUSE:Leap 16.0 | Paket deposu (OSV) |
| opensuse:kernel-64kb | 6.12.0-160000.9.1 · openSUSE:Leap 16.0 | Paket deposu (OSV) |
| opensuse:kernel-azure | 6.12.0-160000.9.1 · openSUSE:Leap 16.0 | Paket deposu (OSV) |
| opensuse:kernel-default | 6.12.0-160000.9.1 · openSUSE:Leap 16.0 | Paket deposu (OSV) |
| opensuse:kernel-default-base | 6.12.0-160000.9.1.160000.2.6 · openSUSE:Leap 16.0 | Paket deposu (OSV) |
| opensuse:kernel-docs | 6.12.0-160000.9.1 · openSUSE:Leap 16.0 | Paket deposu (OSV) |
| opensuse:kernel-kvmsmall | 6.12.0-160000.9.1 · openSUSE:Leap 16.0 | Paket deposu (OSV) |
| opensuse:kernel-obs-build | 6.12.0-160000.9.1 · openSUSE:Leap 16.0 | Paket deposu (OSV) |
| opensuse:kernel-obs-qa | 6.12.0-160000.9.1 · openSUSE:Leap 16.0 | Paket deposu (OSV) |
| opensuse:kernel-rt | 6.12.0-160000.9.1 · openSUSE:Leap 16.0 | Paket deposu (OSV) |
| opensuse:kernel-source | 6.12.0-160000.9.1 · openSUSE:Leap 16.0 | Paket deposu (OSV) |
| opensuse:kernel-syms | 6.12.0-160000.9.1 · openSUSE:Leap 16.0 | Paket deposu (OSV) |
| suse:kernel-64kb | 6.12.0-160000.9.1 · SUSE:Linux Micro 6.2 | Paket deposu (OSV) |
| suse:kernel-azure | 6.12.0-160000.9.1 · SUSE:Linux Enterprise Server 16.0 | Paket deposu (OSV) |
| suse:kernel-default | 4.12.14-122.296.1 · SUSE:Linux Enterprise Live Patching 12 SP5 | Paket deposu (OSV) |
| suse:kernel-default-base | 6.12.0-160000.9.1.160000.2.6 · SUSE:Linux Micro 6.2 | Paket deposu (OSV) |
| suse:kernel-docs | 6.12.0-160000.9.1 · SUSE:Linux Enterprise Server 16.0 | Paket deposu (OSV) |
+7
İstismar durumu
Bilinen kamuya açık istismar yok
Şu an kamuya açık bir istismar görülmedi. Bu, güvende olduğunuz anlamına gelmez; yalnızca eşiğin biraz daha yüksek olduğunu gösterir.
Araştırma bağlamı
Pentester ve araştırmacı için: saldırı profili, puan anlaşmazlığı, zaman çizelgesi, yama commit’leri, kredi, varyant ve zincir adayları, bug bounty kapsamı. Hepsi mevcut veriden türetilir; istismar kodu içermez.
Zaman çizelgesi
Yayından bugüne: kavram kanıtı, Metasploit modülü, CISA KEV ve düzeltme kaydı. Tarihler kaynakların bildirdiği tarihlerdir.
Yayın dışında tarihli olay yok.
FIRST EPSS günlük puanı; yalnızca 0,01 ve üstü değişimler kaydedilir (adım grafiği).
Yama ve commit bağlantıları
Referanslardaki commit, PR ve diff adresleri. Patch-diff ve varyant avı için başlangıç noktası; istismar değil, düzeltmedir.
Referanslarda commit ya da PR bağlantısı yok.
Kredi
Tüm araştırmacılarCNA kaydında adı geçen bulan, bildiren ve analistler. Ada tıkla, aynı araştırmacının diğer kayıtlarını gör.
CNA kaydında kredi yok.
Varyant adayları
Aynı üründe aynı zafiyet sınıfı, 18 ay içinde. Yama kök nedeni kapatmadıysa kardeş hata burada olur.
Gece hesaplanan ilişki yok.
Zincir adayları
Aynı üründe kimlik doğrulama atlatma ile yetki isteyen bir açık kısa aralıkla yayımlanmış: birlikte kimlik doğrulamasız bir yola dönüşebilir.
—
Bug bounty kapsamı
Bilinen herkese açık program yok.
Kaynak: bounty-targets-data (HackerOne, Bugcrowd, Intigriti, YesWeHack herkese açık listeleri).
Teknik detay
Bu kayıt için CVSS vektörü yok; saldırı koşulları çıkarılamıyor.
Zayıflık sınıfı (CWE)
—
Saldırı bağlamı
Bu zafiyet sınıfının (CWE) MITRE CAPEC saldırı desenleri ve ATT&CK teknikleri. Tespit kuralı ve tehdit avı için başlangıç noktası.
Bu CWE için MITRE'de CAPEC/ATT&CK eşlemesi yok.
Değişiklik günlüğü
- Düzeltme✗ → ✓
Takip ettiğiniz kayıtlarda bu değişiklikler bildirim olarak da gelir. →
Referanslar
- git.kernel.org/stable/c/26e5c67deb2e1f42a951f022fdf5b9f7eb747b01
- git.kernel.org/stable/c/548e1f2bac1d4df91a6138f26bb4ab00323fd948
- git.kernel.org/stable/c/83b375c6efef69b1066ad2d79601221e7892745a
- git.kernel.org/stable/c/b26923512dbe57ae4917bafd31396d22a9d1691a
- git.kernel.org/stable/c/bfd17b6138df0122a95989457d8e18ce0b86165e
- git.kernel.org/stable/c/cfd1aa3e2b71f3327cb373c45a897c9028c62b35
- git.kernel.org/stable/c/f19a1390af448d9e193c08e28ea5f727bf3c3049
Üretici bildirimleri ve resmî kayıtlar. İstismar/PoC bağlantıları bilinçli olarak dışarıda bırakıldı.