CVE-2026-33179

EUVD-2026-13794
libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a NULL pointer dereference and memory leak in fuse_uring_init_queue allows a local user to crash the FUSE daemon or cause resource exhaustion. When numa_alloc_local fails during io_uring queue entry setup, the code proceeds with NULL pointers. When fuse_uring_register_queue fails, NUMA allocations are leaked and the function incorrectly returns success. Only the io_uring transport is affected; the traditional /dev/fuse path is not affected. PoC confirmed with AddressSanitizer/LeakSanitizer. This issue has been patched in version 3.18.2.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
GitHub_MCNA
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
libfuse_projectlibfuse
3.18.0 ≤
𝑥
< 3.18.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
fuse3
bookworm
3.14.0-4
fixed
bullseye
3.10.3-2
fixed
forky
3.18.2-1
fixed
sid
3.18.2-1
fixed
trixie
3.17.2-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
fuse
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
questing
not-affected
trusty
not-affected
xenial
not-affected
fuse3
focal
not-affected
jammy
not-affected
noble
not-affected
questing
not-affected