Impact
The vulnerability arises in the Linux kernel’s FUSE io‑uring transport when the code copies request headers directly from the fuse_request slab into user space. Because the slab cache was created without a usercopy whitelist, the_USERCOPY protection and triggers a kernel BUG, leading to a to become unavailable if, effectively providing a denial‑of‑service vector.
Affected Systems
All Linux kernel versions that contain the unpatched fuse io‑uring header copy logic are impacted. The issue affects every distribution that ships a fresh Linux kernel with the FUSE module and io‑uring support enabled, until the patch that records a safe on‑stack copy of the headers is merged.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would require an attacker to be able to generate or manipulate FUSE io‑uring requests on the local system, a privilege typically associated with local or privileged access. If these conditions are met, the system may repeatedly crash, resulting in a denial‑of‑service situation.
OpenCVE Enrichment