CVE-2026-64259 | Linux Kernel up to 6.18.38/7.1.3 fuse-uring fuse_uring_commit_fetch/fuse_uring_send_in_task use after free
A vulnerability marked as very critical has been reported in Linux Kernel up to 6.18.38/7.1.3. The affected element is the function fuse_uring_commit_fetch/fuse_uring_send_in_task of the component fuse-uring. Performing a manipulation results in use after free.
This vulnerability is reported as CVE-2026-64259. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.