Куда я попал?
SECURITM это SGRC система, ? автоматизирующая процессы в службах информационной безопасности. SECURITM помогает построить и управлять ИСПДн, КИИ, ГИС, СМИБ/СУИБ, банковскими системами защиты.
А еще SECURITM это место для обмена опытом и наработками для служб безопасности.

CVE-2025-40220

PUBLISHED 23.05.2026

CNA: Linux

fuse: fix livelock in synchronous file put from fuseblk workers

Обновлено: 23.05.2026
In the Linux kernel, the following vulnerability has been resolved: fuse: fix livelock in synchronous file put from fuseblk workers I observed a hang when running generic/323 against a fuseblk server. This test opens a file, initiates a lot of AIO writes to that file descriptor, and closes the file descriptor before the writes complete. Unsurprisingly, the AIO exerciser threads are mostly stuck waiting for responses from the fuseblk server: # cat /proc/372265/task/372313/stack [<0>] request_wait_answer+0x1fe/0x2a0 [fuse] [<0>] __fuse_simple_request+0xd3/0x2b0 [fuse] [<0>] fuse_do_getattr+0xfc/0x1f0 [fuse] [<0>] fuse_file_read_iter+0xbe/0x1c0 [fuse] [<0>] aio_read+0x130/0x1e0 [<0>] io_submit_one+0x542/0x860 [<0>] __x64_sys_io_submit+0x98/0x1a0 [<0>] do_syscall_64+0x37/0xf0 [<0>] entry_SYSCALL_64_after_hwframe+0x4b/0x53 But the /weird/ part is that the fuseblk server threads are waiting for responses from itself: # cat /proc/372210/task/372232/stack [<0>] request_wait_answer+0x1fe/0x2a0 [fuse] [<0>] __fuse_simple_request+0xd3/0x2b0 [fuse] [<0>] fuse_file_put+0x9a/0xd0 [fuse] [<0>] fuse_release+0x36/0x50 [fuse] [<0>] __fput+0xec/0x2b0 [<0>] task_work_run+0x55/0x90 [<0>] syscall_exit_to_user_mode+0xe9/0x100 [<0>] do_syscall_64+0x43/0xf0 [<0>] entry_SYSCALL_64_after_hwframe+0x4b/0x53 The fuseblk server is fuse2fs so there's nothing all that exciting in the server itself. So why is the fuse server calling fuse_file_put? The commit message for the fstest sheds some light on that: "By closing the file descriptor before calling io_destroy, you pretty much guarantee that the last put on the ioctx will be done in interrupt context (during I/O completion). Aha. AIO fgets a new struct file from the fd when it queues the ioctx. The completion of the FUSE_WRITE command from userspace causes the fuse server to call the AIO completion function. The completion puts the struct file, queuing a delayed fput to the fuse server task. When the fuse server task returns to userspace, it has to run the delayed fput, which in the case of a fuseblk server, it does synchronously. Sending the FUSE_RELEASE command sychronously from fuse server threads is a bad idea because a client program can initiate enough simultaneous AIOs such that all the fuse server threads end up in delayed_fput, and now there aren't any threads left to handle the queued fuse commands. Fix this by only using asynchronous fputs when closing files, and leave a comment explaining why.

БДУ ФСТЭК

Идентификатор Описание
BDU:2026-02789 Уязвимость компонента fs/fuse ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании

Доп. Информация

Product Status

Linux
Product: Linux
Vendor: Linux
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 5a18ec176c934ca1bc9dc61580a5e0e90a9b5733 до 548e1f2bac1d4df91a6138f26bb4ab00323fd948 affected
Наблюдалось в версиях от 5a18ec176c934ca1bc9dc61580a5e0e90a9b5733 до cfd1aa3e2b71f3327cb373c45a897c9028c62b35 affected
Наблюдалось в версиях от 5a18ec176c934ca1bc9dc61580a5e0e90a9b5733 до 83b375c6efef69b1066ad2d79601221e7892745a affected
Наблюдалось в версиях от 5a18ec176c934ca1bc9dc61580a5e0e90a9b5733 до bfd17b6138df0122a95989457d8e18ce0b86165e affected
Наблюдалось в версиях от 5a18ec176c934ca1bc9dc61580a5e0e90a9b5733 до b26923512dbe57ae4917bafd31396d22a9d1691a affected
Наблюдалось в версиях от 5a18ec176c934ca1bc9dc61580a5e0e90a9b5733 до f19a1390af448d9e193c08e28ea5f727bf3c3049 affected
Наблюдалось в версиях от 5a18ec176c934ca1bc9dc61580a5e0e90a9b5733 до 26e5c67deb2e1f42a951f022fdf5b9f7eb747b01 affected
Наблюдалось в версии 9efe56738fecd591b5bf366a325440f9b457ebd6 affected
Наблюдалось в версии 5c46eb076e0a1b2c1769287cd6942e4594ade1b1 affected
Наблюдалось в версии 83e6726210d6c815ce044437106c738eda5ff6f6 affected
Наблюдалось в версии 23d154c71721fd0fa6199851078f32e6bd765664 affected
Наблюдалось в версии ca3edc920f5fd7d8ac040caaf109f925c24620a0 affected
Наблюдалось в версиях от 2.6.32.32 до 2.6.33 affected
Наблюдалось в версиях от 2.6.33.8 до 2.6.34 affected
Наблюдалось в версиях от 2.6.34.10 до 2.6.35 affected
Наблюдалось в версиях от 2.6.35.12 до 2.6.36 affected
Наблюдалось в версиях от 2.6.37.3 до 2.6.38 affected
Linux
Product: Linux
Vendor: Linux
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версии 2.6.38 affected
Наблюдалось в версиях от 0 до 2.6.38 unaffected
Наблюдалось до версии 5.10.* unaffected
Наблюдалось до версии 5.15.* unaffected
Наблюдалось до версии 6.1.* unaffected
Наблюдалось до версии 6.6.* unaffected
Наблюдалось до версии 6.12.* unaffected
Наблюдалось до версии 6.17.* unaffected
Наблюдалось до версии * unaffected
 

Ссылки

Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.