CVE-2026-80856
Received
Received - Intake
fuse: Lock Leak in setattr Writeback Failure
Vulnerability report for CVE-2026-80856, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-04
Last updated on: 2026-09-04
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
fuse: fix invalidate lock leak on setattr writeback failure
fuse_do_setattr() takes filemap_invalidate_lock() for a DAX truncate
(fault_blocked = true) and releases it at the out:/error: labels. But
when a writeback flush is also needed, a write_inode_now() failure
returns directly and leaks the lock, so any later fault or truncate on
the file stalls on the stale rwsem.
For example, truncate(2) on a setuid file reaches fuse_do_setattr()
with both ATTR_SIZE and ATTR_MODE set:
truncate(2)
ββ do_truncate()
ββ dentry_needs_remove_privs() # S_ISUID
ββ notify_change() # KILL_SUID -> ATTR_MODE
ββ fuse_setattr() # no killpriv:
β # ia_valid |= ATTR_MODE
ββ fuse_do_setattr()
ββ filemap_invalidate_lock() # IS_DAX && is_truncate
ββ write_inode_now() # is_wb && ATTR_MODE
ββ if (err) # e.g. daemon -> -EIO
return err # <- lock leaked
Fix this by adding an unlock label that releases the lock before
returning the error, and use it for the fuse_dax_break_layouts()
failure path as well.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| linux | linux_kernel | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |