Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-33150

Use After Free in libfuse
Back to all
CVE

CVE-2026-33150

Use After Free in libfuse

libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a use-after-free vulnerability in the iouring subsystem of libfuse allows a local attacker to crash FUSE filesystem processes and potentially execute arbitrary code. When iouring thread creation fails due to resource exhaustion (e.g., cgroup pids.max), fuseuringstart() frees the ring pool structure but stores the dangling pointer in the session state, leading to a use-after-free when the session shuts down. The trigger is reliable in containerized environments where cgroup pids.max limits naturally constrain thread creation. This issue has been patched in version 3.18.2.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
7.8
-
3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://github.com/libfuse/libfuse/releases/tag/fuse-3.18.2, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33150.json, https://github.com/libfuse/libfuse/security/advisories/GHSA-qxv7-xrc2-qmfx, https://nvd.nist.gov/vuln/detail/CVE-2026-33150, https://github.com/libfuse/libfuse/commit/49fcd891a58f622c098e2ca67d66086f7b213836

Severity

7.8

CVSS Score
0
10

Basic Information

Ecosystem
Base CVSS
7.8
EPSS Probability
0.00009%
EPSS Percentile
0.00953%
Introduced Version
9157d99f17384f362c65b02cec065e0aec5f0b56,0
Fix Available
033844748010a3b8265bf1c90b9ae8ffe4cd9ca7

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading