{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.4-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  fuse-uring: fix EFAULT clobber in fuse_uring_commit  copy_from_user() returns the number of bytes not copied as an unsigned residual on failure (1..sizeof(struct fuse_out_header)). fuse_uring_commit stores that residual in ssize_t err, sets req-\u003eout.h.error to -EFAULT, then jumps to out: with err still holding the positive residual.      err = copy_from_user(\u0026req-\u003eout.h, \u0026ent-\u003eheaders-\u003ein_out,                          sizeof(req-\u003eout.h));     if (err) {         req-\u003eout.h.error = -EFAULT;         goto out;          /* err is the positive residual */     }     ...     out:         fuse_uring_req_end(ent, req, err);  fuse_uring_req_end() then runs      if (error)         req-\u003eout.h.error = error;  which overwrites the just-assigned -EFAULT with the positive residual. FUSE callers such as fuse_simple_request() test err \u003c 0 to detect failure, so the positive value is interpreted as success and the caller proceeds with an uninitialised or partial req-\u003eout.args.  Fix by assigning err = -EFAULT in the failure branch before jumping to out, so fuse_uring_req_end() receives a negative errno and sets req-\u003eout.h.error to -EFAULT.",
  "id": "DEBIAN-CVE-2026-64264",
  "modified": "2026-09-14T16:47:40.723506801Z",
  "published": "2026-07-25T10:17:06.563Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-64264"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-64264"
  ]
}