Linux Kernel FUSE Reference Count Leak Vulnerability in IO-Uring Argument Copies

Vulnerability

A vulnerability in the Linux kernel's FUSE (Filesystem in Userspace) implementation has been addressed. The issue involved a potential reference count leak of payload pages during the copying of FUSE arguments over IO-uring. This vulnerability could lead to improper management of memory references, potentially causing memory-related issues.

Impact

Exploitation of this vulnerability could result in a memory leak, where payload pages are not properly released, potentially leading to increased memory usage and related performance issues.

Remediation

Users can upgrade to the latest version of the Linux kernel to address this vulnerability. The patched version is included in the official Linux kernel repositories.

Added: Jan 13, 2026, 6:19 PM
Updated: Jan 13, 2026, 6:19 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
5.3
remediation
7.7
relevance
2.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.