Improper Check or Handling of Exceptional Conditions in Linux kernel - CVE-2026-64264
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause incorrect handling of a failed request.
The vulnerability exists due to improper error handling in fuse_uring_commit when copying an output header from user memory. A local user can trigger a copy_from_user() failure to cause incorrect handling of a failed request.
The positive residual value can be interpreted as success, causing the caller to proceed with an uninitialised or partially populated req->out.args.