---
id: CVE-2026-80858
title: 'fuse: publish io-uring queues with release semantics'
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  fuse: publish io-uring queues with release semantics

  fuse_uring_create_queue() initializes a fuse_ring_queue and then
  publishes the pointer into ring->queues[qid] with…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 24fe962c86f55347385933a1b06ca71b60854690 <
    a5bb215dbc34b4c6a5e144ea1416bf66450d519f
  - >-
    Linux >= 24fe962c86f55347385933a1b06ca71b60854690 <
    a1bb359c443d048fe5dfd6ca9caf4e3897f3e9aa
  - >-
    Linux >= 24fe962c86f55347385933a1b06ca71b60854690 <
    42df916e5a5f8fb4b60c8cefb54318d1ec02c580
  - Linux 6.14
published: '2026-09-04'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T09:57:11.882Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-80858'
references:
  - url: 'https://git.kernel.org/stable/c/a5bb215dbc34b4c6a5e144ea1416bf66450d519f'
  - url: 'https://git.kernel.org/stable/c/a1bb359c443d048fe5dfd6ca9caf4e3897f3e9aa'
  - url: 'https://git.kernel.org/stable/c/42df916e5a5f8fb4b60c8cefb54318d1ec02c580'
tags:
  - cve.org
epss: 0.00206
epssPercentile: 0.09481
ingestedAt: '2026-09-11T16:45:47.924Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

fuse: publish io-uring queues with release semantics

fuse_uring_create_queue() initializes a fuse_ring_queue and then
publishes the pointer into ring->queues[qid] with WRITE_ONCE() under the
fch->lock. There are several readers that may concurrently be fetching
that pointer locklessly and then deferencing it.

WRITE_ONCE() doesn't ensure ordering of the queue's field
initialization before the ring->queues[qid] pointer assignment. The
queue must be published with smp_store_release() so the field
initialization is guaranteed to happen before.

Readers in paths where the read may happen concurrently with the store
need to use READ_ONCE() because any race involving a plain access is
undefined.

## Affected

- `Linux >= 24fe962c86f55347385933a1b06ca71b60854690 < a5bb215dbc34b4c6a5e144ea1416bf66450d519f`
- `Linux >= 24fe962c86f55347385933a1b06ca71b60854690 < a1bb359c443d048fe5dfd6ca9caf4e3897f3e9aa`
- `Linux >= 24fe962c86f55347385933a1b06ca71b60854690 < 42df916e5a5f8fb4b60c8cefb54318d1ec02c580`
- `Linux 6.14`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
