Impact
In the Linux kernel the function fuse_fill_super_submount() fails to verify that the inode returned by fuse_iget() is non‑NULL. When memory pressure causes fuse_iget() to return NULL, the null pointer is passed to get_fuse_inode() and later dereferenced during a decrement of fi->nlookup. This results in a kernel oops and a crash of the process attempting the mount or FUSE auto‑submount operation. The crash is a denial‑of‑service that does not provide a direct privilege‑escalation path based on the available information.
Affected Systems
All Linux kernel releases that contain the un‑patched fuse_fill_super_submount() implementation are potentially affected. No specific version numbers are listed in the advisory, so any kernel in which this code exists would be vulnerable until the kernel update that introduces the NULL check and error handling is applied.
Risk and Exploitability
The EPSS score for this flaw is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low to moderate likelihood of exploitation. The flaw requires a local trigger: an attacker must force a FUSE auto‑submount under memory‑pressure conditions for the root inode allocation to fail. While the attack vector is narrow, systems that run unpatched kernels and rely on FUSE submounts could be taken down by a local attacker or by a compromised process that can manipulate memory pressure.
OpenCVE Enrichment
Debian DLA
Debian DSA