Use-after-free in Linux kernel - CVE-2026-53381
Published: July 21, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in fuse_release_end() during virtiofs auto_submount unmount processing when releasing files during submount unmount after the superblock has already been destroyed. A local user can trigger submount unmount activity to cause a denial of service.
The issue affects the virtiofs auto_submounts case, where the wait counter is tracked per connection rather than per superblock.
Affected software
How to mitigate CVE-2026-53381
External References
- https://git.kernel.org/stable/c/06b41351779e9289e8785694ade9042ae85e41ea
- https://git.kernel.org/stable/c/0b809199ff87c44487e516a725dd4be2185712ce
- https://git.kernel.org/stable/c/1cc0e3a0c6499aaaa2f21a4fcbba388486afb25e
- https://git.kernel.org/stable/c/2181a09ba980f142650fb053666350ead4471cfe
- https://git.kernel.org/stable/c/2abfd3ffbd9452f72535d96ff3982b3ab1f8f2f9
- https://git.kernel.org/stable/c/39a2b95e008665c14f84e50ed411d898df7cd11b
- https://git.kernel.org/stable/c/607a1d4c42f649e6197567c0448fd9ebb316cd42
- https://git.kernel.org/stable/c/97c4691653d145dcc699eca5d3aba3219a520f1f
- https://git.kernel.org/stable/c/e09412a714bcd49375198427bb4aa005037a9d6f