What is CVE-2026-64261?
A use-after-free vulnerability in the Linux kernel's fuse-uring subsystem (CVE-2026-64261) occurs when `fuse_uring_async_stop_queues` accesses a ring structure after its last reference has been dropped. This can lead to instability or potential exploitation, and updating the kernel is the recommended mitigation.
Azərbaycanca: Linux kernel-də 'fuse-uring' alt sistemində aşkarlanan CVE-2026-64261 zəifliyi, `fuse_uring_async_stop_queues` funksiyasında istifadə-sonrası-sərbəst (use-after-free) vəziyyətinə səbəb ola bilər. Bu, ring strukturu artıq məhv edildikdən sonra ona giriş cəhdi nəticəsində baş verir. Təsirə məruz qalan sistemlərdə kernel-i yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-416
FAQ2
Which subsystem of the Linux kernel does CVE-2026-64261 affect?
This vulnerability affects the 'fuse-uring' subsystem.
What type of vulnerability is CVE-2026-64261?
It is a use-after-free vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.