CVE-2026-64267
Last modified
CVE-2026-64267 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: fuse: avoid 32-bit prune notification count wrap FUSE_NOTIFY_PRUNE validates the nodeid payload length with: size - sizeof(outarg) != outarg.count * sizeof(u64) On 32-bit kernels, size_t is also 32 bits, so the daemon-controlled count multiplication can wrap. A prune notification with count 0x20000000 and no nodeid payload passes the check, enters the copy loop, and asks the device copy path to read nodeids that are not present in the userspace write buffer. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: fuse: avoid 32-bit prune notification count wrap FUSE_NOTIFY_PRUNE validates the nodeid payload length with: size - sizeof(outarg) != outarg.count * sizeof(u64) On 32-bit kernels, size_t is also 32 bits, so the daemon-controlled count multiplication can wrap. A prune notification with count 0x20000000 and no nodeid payload passes the check, enters the copy loop, and asks the device copy path to read nodeids that are not present in the userspace write buffer. In QEMU this reaches the fuse_copy_fill() BUG_ON(!err) path. Validate the payload length with array_size() instead. That accepts exactly the same valid messages, but avoids wrapping arithmetic before the copy loop consumes the count.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.18, < 6.18.39 |
| Linux | Linux Kernel | >= 6.19, < 7.1.4 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-64267?
How severe is CVE-2026-64267?
How do I fix CVE-2026-64267?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-64261In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64262In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-64263In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-64264In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-64265In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64266In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64268In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-64269In the Linux kernel, the following vulnerability has been re…9.1
- CVE-2026-6427The a3 Lazy Load plugin for WordPress is vulnerable to Store…6.4
- CVE-2026-64270In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64271In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64272In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-64267?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
