Description
In the Linux kernel, the following vulnerability has been resolved:

fuse: copy request headers via a stack buffer for io-uring

The fuse-io-uring transport copies req->in.h out to the ring in
fuse_uring_copy_to_ring() and req->out.h back in fuse_uring_commit().
Both headers live inside the fuse_request slab object, whose cache
(fuse_req_cachep) is created without a usercopy whitelist, so copying
them directly to/from userspace trips CONFIG_HARDENED_USERCOPY and
panics:

usercopy: Kernel memory exposure attempt detected from SLUB object
'fuse_request' (offset 56, size 40)!
kernel BUG at mm/usercopy.c:102!
Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI
RIP: 0010:usercopy_abort (mm/usercopy.c:90)
Call Trace:
__check_heap_object (mm/slub.c:8268)
__check_object_size (mm/usercopy.c:197 mm/usercopy.c:258 mm/usercopy.c:223)
copy_header_to_ring (fs/fuse/dev_uring.c:618)
fuse_uring_prepare_send (fs/fuse/dev_uring.c:776 fs/fuse/dev_uring.c:785)
fuse_uring_send_in_task (fs/fuse/dev_uring.c:1306)
tctx_task_work_run (io_uring/tw.c:96)
task_work_run (kernel/task_work.c:233)
io_run_task_work (io_uring/tw.h:84)
io_cqring_wait (io_uring/wait.c:278)
__do_sys_io_uring_enter (io_uring/io_uring.c:2685)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)

Bounce both headers through an on-stack copy so the usercopy touches
stack memory, not the slab object.
Published: 2026-09-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel panic
Action: Apply patch
AI Analysis

Impact

The vulnerability arises in the Linux kernel’s FUSE io‑uring transport when the code copies request headers directly from the fuse_request slab into user space. Because the slab cache was created without a usercopy whitelist, the_USERCOPY protection and triggers a kernel BUG, leading to a to become unavailable if, effectively providing a denial‑of‑service vector.

Affected Systems

All Linux kernel versions that contain the unpatched fuse io‑uring header copy logic are impacted. The issue affects every distribution that ships a fresh Linux kernel with the FUSE module and io‑uring support enabled, until the patch that records a safe on‑stack copy of the headers is merged.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would require an attacker to be able to generate or manipulate FUSE io‑uring requests on the local system, a privilege typically associated with local or privileged access. If these conditions are met, the system may repeatedly crash, resulting in a denial‑of‑service situation.

Generated by OpenCVE AI on September 21, 2026 at 02:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that contains the fuse_uring copy fix.
  • Disable io‑uring support for the FUSE module until an updated kernel is deployed.
  • If upgrade or disabling io‑uring is not immediately feasible rapid reboot or migration to a non‑FUSE filesystem to avoid prolonged downtime.

Generated by OpenCVE AI on September 21, 2026 at 02:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-501
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: fuse: copy request headers via a stack buffer for io-uring The fuse-io-uring transport copies req->in.h out to the ring in fuse_uring_copy_to_ring() and req->out.h back in fuse_uring_commit(). Both headers live inside the fuse_request slab object, whose cache (fuse_req_cachep) is created without a usercopy whitelist, so copying them directly to/from userspace trips CONFIG_HARDENED_USERCOPY and panics: usercopy: Kernel memory exposure attempt detected from SLUB object 'fuse_request' (offset 56, size 40)! kernel BUG at mm/usercopy.c:102! Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI RIP: 0010:usercopy_abort (mm/usercopy.c:90) Call Trace: __check_heap_object (mm/slub.c:8268) __check_object_size (mm/usercopy.c:197 mm/usercopy.c:258 mm/usercopy.c:223) copy_header_to_ring (fs/fuse/dev_uring.c:618) fuse_uring_prepare_send (fs/fuse/dev_uring.c:776 fs/fuse/dev_uring.c:785) fuse_uring_send_in_task (fs/fuse/dev_uring.c:1306) tctx_task_work_run (io_uring/tw.c:96) task_work_run (kernel/task_work.c:233) io_run_task_work (io_uring/tw.h:84) io_cqring_wait (io_uring/wait.c:278) __do_sys_io_uring_enter (io_uring/io_uring.c:2685) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) Bounce both headers through an on-stack copy so the usercopy touches stack memory, not the slab object.
Title fuse: copy request headers via a stack buffer for io-uring
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:42:17.576Z

Reserved: 2026-08-26T14:34:25.803Z

Link: CVE-2026-80946

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:00.180

Modified: 2026-09-11T20:19:00.180

Link: CVE-2026-80946

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:17Z

Links: CVE-2026-80946 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T03:00:12Z

Weaknesses