---
id: CVE-2026-64266
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  fuse: re-lock request before returning from fuse_ref_folio()

  fuse_ref_folio() unlocks the request but does not re-lock it before
  returning
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  fuse: re-lock request before returning from fuse_ref_folio()

  fuse_ref_folio() unlocks the request but does not re-lock it before
  returning. fuse_chan_abort() can end t…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
published: '2026-07-25'
updated: '2026-07-27'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-64266'
references:
  - url: 'https://git.kernel.org/stable/c/0e4a5a000123d81234e27a2f8187688cf608f755'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/1ca605cfa59377f0143fb35b5b01360f37d1b7c4'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/1f9156714592356b4fda57beac7eab9c2a462dd3'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5630da218a45ba80f0aba0846cbe8aa655da122b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/65a1c2551f7e16085acbb54aedde1feaa559ba7a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b5befa80fdbe287a98480effed9564712924add5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/be353caffa8640f5e25fb3714ce8b0cef5e410e5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e6aa539720c3d8def69683ed0c07cf9faea4e8be'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00164
epssPercentile: 0.04916
ingestedAt: '2026-07-27T06:16:49.696Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

fuse: re-lock request before returning from fuse_ref_folio()

fuse_ref_folio() unlocks the request but does not re-lock it before
returning. fuse_chan_abort() can end the request and the async end
callback (eg fuse_writepage_free()) can free the args while the
subsequent copy chain logic after fuse_ref_folio() accesses them,
leading to use-after-free issues.

Fix this by locking the request in fuse_ref_folio() before returning.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
