NULL pointer dereference in Linux kernel - CVE-2026-64263
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in the fuse-uring request handling code when processing cancellation of available entries moved to the ent_in_userspace list. A local user can trigger cancellation of a crafted entry state to cause a denial of service.
The crash occurs because the first entry on the ent_in_userspace list may be dereferenced even when no fuse request is attached.