logo

Critical libfuse io_uring Vulnerabilities Threaten Linux and Kubernetes Infrastructure

ID: 104ef7f2-acb6-569e-9144-ac4a7c594d34

STIX ID: report--104ef7f2-acb6-569e-9144-ac4a7c594d34

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-30

Date Updated: 2026-04-23

Author: Ddos

...
...

Two vulnerabilities were disclosed in libfuse's io_uring transport (CVE-2026-33179 and CVE-2026-33150) impacting libfuse 3.18.0 through 3.19.0-rc0 when io_uring is enabled: the first causes local denial-of-service and a persistent memory leak due to unchecked allocation failures, while the second can allow an attacker to exploit a freed 192-byte heap chunk to cause arbitrary code execution during session teardown. Systems using FUSE daemons (often running as root), particularly Kubernetes CSI drivers constrained by cgroup pids.max, are called out as at-risk; administrators are urged to upgrade to libfuse 3.18.2 to remediate both flaws.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.