logo

Linux FUSE Vulnerability Allows Unprivileged Users to Pop a Root Shell

ID: 19aa75ce-1f0d-5f7b-bc78-edcaa597dd6d

STIX ID: report--19aa75ce-1f0d-5f7b-bc78-edcaa597dd6d

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-07-10

Date Updated: 2026-07-21

Author: Divya

...
...

A FUSE directory-caching bug (CVE-2026-31694) permits an unprivileged user who can mount a FUSE filesystem to craft an oversized directory entry that overflows a 4 KiB page by 24 bytes, enabling reliable local privilege escalation by corrupting the page cache of a cached SUID binary (demonstrated against /usr/bin/su on vulnerable kernels). The flaw affects kernels from v6.16-rc1 onward (where the FUSE readdir buffer was increased), has an upstream patch that prevents caching dirents larger than PAGE_SIZE, and administrators are urged to apply kernel updates and reduce FUSE/unprivileged-mount exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.