---
id: CVE-2026-53167
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios

  FUSE_NOTIFY_RETRIEVE must be limited to uptodate folios; !uptodate folios
  can contain uninitialized data.
  Since FUS…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios

  FUSE_NOTIFY_RETRIEVE must be limited to uptodate folios; !uptodate folios
  can contain uninitialized data.
  Since FUS…
severity: none
published: '2026-06-25'
updated: '2026-07-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-53167'
references:
  - url: 'https://git.kernel.org/stable/c/1fb8735a3a4d894f8c1f90b741a3ab1d3817f9bd'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/4e14f29473eda18fb2af082dd2fd4c12139862cd'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/4e3d1b2c48ca6c55f1e9ca7f8dccc76f120f276c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/56763afa013444a9d84ca1b74e4b7130942177ba'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/651801d75ad0897dbd331b3cc6a4da3e78f60d42'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/68a9282d5ea5b8780d59122505ad633e6daede90'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8bef2f840b43e0879478fe3aaa9ff2f0b80798a5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/feafe8ccb1584254f59fbd4946d6ca7ef1e3e99c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00125
epssPercentile: 0.02572
ingestedAt: '2026-07-04T12:56:09.639Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios

FUSE_NOTIFY_RETRIEVE must be limited to uptodate folios; !uptodate folios
can contain uninitialized data.
Since FUSE_NOTIFY_RETRIEVE is intended to only return data that is already
in the page cache and not wait for data from the FUSE daemon, treat
!uptodate folios as if they weren't present.

This only has security impact on systems that don't enable automatic
zero-initialization of all page allocations via
CONFIG_INIT_ON_ALLOC_DEFAULT_ON or init_on_alloc=1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
