What is CVE-2026-64258?
A NULL pointer dereference vulnerability exists in the `fuse-uring` component of the Linux kernel when request-less entries remain in the `ent_w_req_queue` queue. If copying into the userspace ring buffer fails, a request is terminated but the entry is left behind, potentially causing a system crash. Affected systems should apply the kernel update.
Azərbaycanca: Linux kernel-də `fuse-uring` komponentində `ent_w_req_queue` növbəsində sorğusuz (`request-less`) qeydlər qaldıqda NULL pointer dereference zəifliyi yaranır. İstifadəçi ring buferinə kopyalama uğursuz olduqda sorğu dayandırılır, lakin qeyd qalır və bu, sistemin çökməsinə səbəb ola bilər. Təsirə məruz qalan sistemlərdə kernel yenilənməsi tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-476
FAQ2
In which component of the Linux kernel was CVE-2026-64258 discovered?
The vulnerability was discovered in the `fuse-uring` component of the Linux kernel.
What could happen if CVE-2026-64258 is exploited?
Exploitation results in a NULL pointer dereference that can cause a system crash.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.