Data Race Vulnerability in Linux Kernel Affecting Multiple Architectures
CVE-2026-64588
What is CVE-2026-64588?
A data race vulnerability exists in the Linux kernel's fuse-uring implementation, primarily affecting weakly-ordered architectures. Improper memory reordering can allow a CPU to access a stale function pointer, potentially leading to system instability or unauthorized memory access. The vulnerability arises from inadequate atomic operations around the ring status checks, where updates do not consistently guarantee visibility across multiple CPUs. To mitigate this, the code will be updated to utilize proper memory barriers to ensure that stores and loads maintain the necessary order, hence protecting the kernel from such race conditions.
Affected Version(s)
Linux c2c9af9a0b13261c36909036057a116f2edb5e1a
Linux c2c9af9a0b13261c36909036057a116f2edb5e1a
Linux c2c9af9a0b13261c36909036057a116f2edb5e1a < 46725a0056c884cf58a6897f222892807327d82d