Improper locking in Linux kernel - CVE-2026-31713

 

Improper locking in Linux kernel - CVE-2026-31713

Published: May 2, 2026


Vulnerability identifier: #VU128980
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-31713
CWE-ID: CWE-667
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of a fatal signal in fuse sync initialization in the FUSE filesystem mount handling when initializing a FUSE filesystem with sync init while the server exits during FUSE_INIT processing. A local user can trigger a mount operation under these conditions to cause a denial of service.

The issue causes the filesystem creation to hang because the mounting thread keeps the device file descriptor open, preventing an abort from occurring.


Affected software

Linux kernel
Ubuntu
linux (Ubuntu package)
linux-azure (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-raspi (Ubuntu package)

How to mitigate CVE-2026-31713

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Ubuntu package) - update to 7.0.0-27.27
linux-azure (Ubuntu package) - addressed in versions 7.0.0-1009.9, 7.0.0-1010.10
linux-nvidia (Ubuntu package) - update to 7.0.0-1013.13
linux-raspi (Ubuntu package) - update to 7.0.0-1014.14

External References

Related Security Bulletins