CVE-2026-53381

Updated on 19 Jul 2026

Severity

7.8 High severity

Details

CVSS score
7.8
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved:

virtiofs: fix UAF on submount umount

iput() called from fuse_release_end() can Oops if the super block has already been destroyed. Normally this is prevented by waiting for num_waiting to go down to zero before commencing with super block shutdown.

This only works, however, for the last submount instance, as the wait counter is per connection, not per superblock.

Revert to using synchronous release requests for the auto_submounts case, which is virtiofs only at this time.

Details

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
Amazon Linux 2023 Ready For Release
Debian 11 Planned
Debian 11 cloud Planned
Debian 13 Planned