Impact
The Linux kernel’s fuse module contains a race condition where the function reading the FUSE_INIT_REPLY fails to verify the presence of the FUSE_OVER_IO_URING flag before accepting any IORING_OP_URING_CMD. This missing check allows the fuse_uring_ready() barrier to be bypassed, thereby letting I/O operations proceed and potentially deadlock the fuse channel background lock with the queue lock. As a result the affected FUSE server can hang services that depend on fuse io-uring, creating a denial‑of‑service scenario.
Affected Systems
All Linux kernel builds that compile with the fuse module and have not incorporated the patch that restores the proper flag check are potentially vulnerable. The issue applies generically to the Linux kernel rather than to a specific distribution; any distribution shipping a kernel version without this fix is impacted. The specific vendor name is Linux:Linux.
Risk and Exploitability
The EPSS score is reported as < 1%, indicating a very low percentage of anticipated live exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would likely need local or elevated privileges to send the malformed fuse commands that trigger the deadlock, so the attack vector is inferred to be local. Given the lack of remote triggers, the overall risk is moderate, but systems that enable fuse io-uring should apply the fix promptly to avoid availability loss.
OpenCVE Enrichment