Improper Enforcement of Behavioral Workflow in Linux kernel - CVE-2026-90095
Published: September 19, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state validation in fuse_uring_cmd() when processing IORING_OP_URING_CMD requests on a FUSE connection that did not negotiate FUSE_OVER_IO_URING while I/O is active. A local user can issue an IORING_OP_URING_CMD request to cause a deadlock.