{"schema_version":"1.7.5","id":"CVE-2026-53388","published":"2026-07-19T11:59:34.456Z","modified":"2026-07-23T09:59:45.899647376Z","related":["openSUSE-SU-2026:11339-1"],"summary":"fuse: re-lock request before replacing page cache folio","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: re-lock request before replacing page cache folio\n\nfuse_try_move_folio() unlocks the request on entry but does not\nre-lock it on the success path. This means fuse_chan_abort() can end the\nrequest and free the fuse_io_args (eg fuse_readpages_end()) while the\nsubsequent copy chain logic after fuse_try_move_folio() accesses the\nfuse_io_args, leading to use-after-free issues.\n\nFix this by calling lock_request() before replace_page_cache_folio().\nThis ensures the request is locked on the success path which will\nprevent the fuse_io_args from being freed while the later copying logic\nruns, and also ensures that the ap->folios[i]->mapping is never null\nsince ap->folios[i] will always point to the newfolio after\nreplace_page_cache_folio().","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"ce534fb052928ce556639d7ecf01cbf4e01321e1"},{"fixed":"7c18691e0cfda29672f79bafde8abdb7710674f6"},{"fixed":"5927b43a4f8d89e86930f524bf63e9c7e66f61b4"},{"fixed":"030fe3e9d8abdee303dd7e9e42f45082d382a407"},{"fixed":"46473ddccdc5065033e397d6e62c280dbcd3d9c2"},{"fixed":"af2892249d982a1c036ca456cc135374e68b6677"},{"fixed":"0223f452532d9cd8a5e87c45de828fd93c99bd25"},{"fixed":"e28db6ac4792d065ab32565fd9f0a2361c3d4666"},{"fixed":"a078484921052d0badd827fcc2770b5cfc1d4120"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53388.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.6.35"},{"fixed":"5.15.211"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.177"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.144"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.95"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.37"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.0.14"}]},{"type":"ECOSYSTEM","events":[{"introduced":"7.1.0"},{"fixed":"7.1.2"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53388.json"}}],"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/0223f452532d9cd8a5e87c45de828fd93c99bd25"},{"type":"WEB","url":"https://git.kernel.org/stable/c/030fe3e9d8abdee303dd7e9e42f45082d382a407"},{"type":"WEB","url":"https://git.kernel.org/stable/c/46473ddccdc5065033e397d6e62c280dbcd3d9c2"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5927b43a4f8d89e86930f524bf63e9c7e66f61b4"},{"type":"WEB","url":"https://git.kernel.org/stable/c/7c18691e0cfda29672f79bafde8abdb7710674f6"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a078484921052d0badd827fcc2770b5cfc1d4120"},{"type":"WEB","url":"https://git.kernel.org/stable/c/af2892249d982a1c036ca456cc135374e68b6677"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e28db6ac4792d065ab32565fd9f0a2361c3d4666"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53388.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53388"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53388.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}