---
id: CVE-2026-90139
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  fuse: check for NULL root inode in fuse_fill_super_submount

  fuse_iget() can return NULL when its inode allocation fails, but
  fuse_fill_super_submount() passed the resu…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  fuse: check for NULL root inode in fuse_fill_super_submount

  fuse_iget() can return NULL when its inode allocation fails, but
  fuse_fill_super_submount() passed the resu…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 1866d779d5d2abae59d304e809600ca3ca8d0071 <
    17120c5bfb16808509ea18d7fab6027802d93eba
  - >-
    Linux >= 1866d779d5d2abae59d304e809600ca3ca8d0071 <
    e0b7f2922f6bd4c23cbddb7d1fc2bada570d27d1
  - >-
    Linux >= 1866d779d5d2abae59d304e809600ca3ca8d0071 <
    a5129155ca9fba40d77ff19ffead8244e88d6f9c
  - >-
    Linux >= 1866d779d5d2abae59d304e809600ca3ca8d0071 <
    509f4a09bae7f03c87f67f053648874a5e177867
  - >-
    Linux >= 1866d779d5d2abae59d304e809600ca3ca8d0071 <
    928f659a3e3650978a5b4829cc982324f72b474b
  - Linux 5.10
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:17:06.523'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90139'
references:
  - url: 'https://git.kernel.org/stable/c/17120c5bfb16808509ea18d7fab6027802d93eba'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/509f4a09bae7f03c87f67f053648874a5e177867'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/928f659a3e3650978a5b4829cc982324f72b474b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a5129155ca9fba40d77ff19ffead8244e88d6f9c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e0b7f2922f6bd4c23cbddb7d1fc2bada570d27d1'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.878Z'
epss: 0.00209
epssPercentile: 0.09796
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

fuse: check for NULL root inode in fuse_fill_super_submount

fuse_iget() can return NULL when its inode allocation fails, but
fuse_fill_super_submount() passed the result straight to get_fuse_inode()
and decremented fi->nlookup without checking it:

        root = fuse_iget(sb, parent_fi->nodeid, ...);
        fi = get_fuse_inode(root);
        fi->nlookup--;

Inside fuse_iget() the inode allocation can fail and return NULL.  The
submount root takes the iget5_locked() path, whose alloc_inode() can fail
under memory pressure (the auto-submount branch can fail the same way in
new_inode() or fuse_alloc_submount_lookup()):

        inode = iget5_locked(sb, nodeid, fuse_inode_eq, fuse_inode_set,
                             &nodeid);
        if (!inode)
                return NULL;

A NULL root makes get_fuse_inode() a container_of() on NULL and the
nlookup decrement a write to a bogus address, oopsing the mount.  With
CONFIG_KASAN the following null pointer dereference is reported when the
root inode allocation of an auto-submount fails (e.g. under memory
pressure):

==================================================================
BUG: KASAN: null-ptr-deref in fuse_get_tree_submount+0x656/0x8b0
Read of size 8 at addr 00000000000002b0 by task ls/942
CPU: 0 PID: 942 Comm: ls Tainted: G W 6.6 #15
Call Trace:
 <TASK>
 fuse_get_tree_submount+0x656/0x8b0
 vfs_get_tree+0x48/0x140
 fc_mount+0x13/0x50
 fuse_dentry_automount+0x7a/0xb0
 __traverse_mounts+0xca/0x330
 step_into+0x339/0xac0
 path_lookupat+0xc5/0x2f0
 filename_lookup+0x163/0x2a0
 vfs_statx+0xd5/0x200
 do_statx+0x83/0xd0
 __x64_sys_statx+0xa0/0xc0
 do_syscall_64+0x37/0x90
 entry_SYSCALL_64_after_hwframe+0x78/0xe2
 </TASK>
==================================================================

Return -ENOMEM instead; the caller tears down the partially built
superblock on error, matching the other error returns in this
function.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
