From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C0E24511192 for ; Fri, 4 Sep 2026 15:59:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788537554; cv=none; b=pxvpkyMqjZuycMrsDR53bNkHo0ayAaYJw7uuN/K8/tlAzVvbzHIyn8vom1b+lsmVx/74VelGxX6ppUTpEzh9jcUszA2yhNiyuwSWYjVGqiLDfeDdE4XGUQQHrYs5s8h/rhExfk0AyKIGpKpIYshLU0eLhYJh69HDDPpFZgRLzrU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788537554; c=relaxed/simple; bh=gSwauBLo/y4aYcB+QjCcynC+9rcaci7nlscSq0KAdZk=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=nn6Z3SvxpBMWJAJMXNUcb4Oh8eFgpc/3MRzmFV4ybbIAeAXSEPkyUg2om6AKgLvzWnKAefZfNhk1HUaDs7eXCL+Qz6HYKMviymorzQ1r3fWETlrGhLCpOJmdo8gyyFJrfgRLpsiHMGZXUKtUw50ORhnWc44ajko1Cg+H7Y6PlaQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=anMG7pUn; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="anMG7pUn" Received: by smtp.kernel.org (Postfix) with ESMTPSA id E4EE01F00A3F; Fri, 4 Sep 2026 15:59:10 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1788537551; bh=UBbIGLbIXnpJYI5iDC4pXot5yBvRc5g8u/wryxTkDR8=; h=From:To:Cc:Subject:Date:Reply-To; b=anMG7pUneBA3DCCUQgIo4iE8+XpwYwiUL2y30ENXFmv3cuBtzvXhIsBX+XU2KA9pB gT8ptJZl5QmPiJRMNGG0kvp6sldWeraH+tUwMdWlZm+O5JD2dUKSBtS0aW8RaFCtLN Iu9BB3DQsOanYJS2PdKqP2Ns9Lqb0Xlafjo9nfbE= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80860: fuse: fix race between interrupt and resend Date: Fri, 4 Sep 2026 17:53:27 +0200 Message-ID: <2026090402-CVE-2026-80860-4b85@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2568; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=IsdzENDuWu5jYbnZasay+i2luKogzJX+FgwbqVoZx8U=; b=owGbwMvMwCRo6H6F97bub03G02pJDFmzXsad3nz3/WwXjSmBu19f0/rp2vPcTkZhvtRR1dtGo Vyy3gdfd8SyMAgyMciKKbJ82cZzdH/FIUUvQ9vTMHNYmUCGMHBxCsBE6rcxzK/6fypV9v7MGt12 Ex5tRWuRaJmznQzzdI1W7PXeEXJQ61WtyDyR0thFe+w0AA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: fuse: fix race between interrupt and resend After commit f8fce75fedf7 ("fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req") the WARN_ON(!list_empty(&req->intr_entry)) in fuse_request_free() still triggers due to the following race: In request_wait_answer() if (test_bit(FR_SENT, &req->flags)) -> returns true In fuse_chan_resend() clear_bit(FR_SENT, &req->flags) In request_wait_answer() queue_interrupt(req) Fix by: - move clearing FR_SENT inside fpq->lock - move setting FR_PENDING inside fiq->lock - recheck FR_SENT after acquiring fiq->lock in fuse_dev_queue_interrupt() The Linux kernel CVE team has assigned CVE-2026-80860 to this issue. Affected and fixed versions =========================== Issue introduced in 7.2 with commit f8fce75fedf73ac72aa09163deb8f4291fdcaad2 and fixed in 7.2.3 with commit 26fbe4bc3ef3ab0200407681cbef182af5d151de Issue introduced in 7.2 with commit f8fce75fedf73ac72aa09163deb8f4291fdcaad2 and fixed in 7.3-rc1 with commit ed9c881f3b498383f73c42712b359419da42a7b0 Issue introduced in 6.12.96 with commit 1d8ecd0cd696a5df0b2f72046a4ccee5d2a8ec2c Issue introduced in 6.18.39 with commit 7366e6f4d2b4c7002b13fb01219e83679dad4127 Issue introduced in 7.1.4 with commit 893479015cb6442fd389d3b553ab3036c9541715 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80860 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: fs/fuse/dev.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/26fbe4bc3ef3ab0200407681cbef182af5d151de https://git.kernel.org/stable/c/ed9c881f3b498383f73c42712b359419da42a7b0