CVE-2026-33150Disclosure(libfuse_project / libfuse)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch libfuse_project libfuse systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a use-after-free vulnerability in the io_uring subsystem of libfuse allows a local attacker to crash FUSE filesystem processes and potentially execute arbitrary code. When io_uring thread creation fails due to resource exhaustion (e.g., cgroup pids.max), fuse_uring_start() frees the ring pool structure but stores the dangling pointer in the session state, leading to a use-after-free when the session shuts down. The trigger is reliable in containerized environments where cgroup pids.max limits naturally constrain thread creation. This issue has been patched in version 3.18.2.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416CWE-825

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libfuse

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 2 mentions (2026-03-21); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Products
libfuse

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-03-21: 2Mentions · 2026-03-24: 2Mentions · 2026-03-30: 1Mentions · 2026-03-31: 1PoC Mentioned / Linked · 2026-03-24: 2Patch / Workaround · 2026-03-21: 1Patch / Workaround · 2026-03-30: 1Technical Details · 2026-03-21: 2Technical Details · 2026-03-24: 2Technical Details · 2026-03-30: 1Technical Details · 2026-03-31: 103-2103-2403-3003-31
Signal classification3 categories
Disclosure
350.0%
PoC
233.3%
Patch
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-212
Disclosure2
2026-03-242
PoC2
2026-03-301
Patch1
2026-03-311
Disclosure1
Full discourse6 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    libfuse: io_uring memory safety vulnerabilities https://www.openwall.com/lists/oss-security/2026/03/21/2 Affected versions: libfuse >= 3.18.0, < 3.18.2 Fixed in: libfuse 3.18.2 CVE-2026-33150: Use-After-Free CVE-2026-33179: NULL Pointer Dereference + Memory Leak

    Post summary

    The note announces two libfuse memory‑safety CVEs (Use-After-Free and NULL pointer dereference), lists affected and fixed versions, and confirms a patch, with no PoC or exploitation details.

    0501171.8K
    4.4K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Researchers uncover two flaws in libfuse's io_uring transport (CVE-2026-33150 & 33179). Impacting Kubernetes CSI drivers, these bugs allow RCE and DoS. Patch now! #libfuse #LinuxSecurity #CyberSecurity #Kubernetes #io_uring #CVE #InfoSec #CloudSecurity https://securityonline.info/libfuse-io-uring-vulnerabilities-cve-2026-33150-cve-2026-33179/ https://t.co/meyHCKpXto

    Post summary

    Researchers discovered RCE and DoS vulnerabilities in libfuse’s io_uring transport affecting Kubernetes CSI drivers; patches have been released to mitigate the issue.

    031111562
    12.3K followersView on X
  • CSIRT Italia@csirt_it
    PoC

    ‼️ #Libfuse: disponibile #PoC per lo sfruttamento delle CVE-2026-33150 e CVE-2026-33179 Rischio: 🔴 Tipologia: 🔸 Arbitrary Code Execution 🔸 Privilege Escalation 🔸 Denial of Service 🔗 https://www.acn.gov.it/portale/w/libfuse-disponibile-poc-per-lo-sfruttamento-delle-cve-2026-33150-e-cve-2026-33179 🔄 Aggiornamenti disponibili 🔄 https://t.co/LmbQh1oLhD

    Post summary

    The post confirms a proof‑of‑concept for the two Libfuse CVEs is available, indicating potential arbitrary code execution, privilege escalation, and denial‑of‑service, but no exploit code or patches are mentioned.

    01050192
    8.8K followersView on X
  • kinneko@kinneko
    Disclosure

    Critical libfuse io_uring Vulnerabilities Threaten Linux and Kubernetes Infrastructure https://securityonline.info/libfuse-io-uring-vulnerabilities-cve-2026-33150-cve-2026-33179/

    Post summary

    The article announces critical libfuse io_uring vulnerabilities (CVE‑2026‑33150 and CVE‑2026‑33179) that could threaten Linux and Kubernetes infrastructure.

    00002119
    2.8K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33150 libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a use-after-free vulnerability in the io_uring subsystem of l… https://www.cve.org/CVERecord?id=CVE-2026-33150

    Post summary

    The text announces CVE‑2026‑33150 as a use‑after‑free flaw in libfuse’s io_uring subsystem affecting versions 3.18.0 to 3.18.1.

    01010164
    56.8K followersView on X
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼️ #Libfuse: disponibile #PoC per lo sfruttamento delle CVE-2026-33150 e CVE-2026-33179 Rischio: 🔴 Tipologia: 🔸 Arbitrary Code Execution 🔸 Privilege Escalation 🔸 Denial of Service 🔗 https://www.acn.gov.it/portale/w/libfuse-disponibile-poc-per-lo-sfruttamento-delle-cve-2026-33150-e-cve-2026-33179 🔄 Aggiornamenti disponibi… https://t.co/STp5RX5LUP

    Post summary

    The tweet announces the availability of a Proof‑of‑Concept for CVE‑2026‑33150 and CVE‑2026‑33179 affecting libfuse, noting the vulnerabilities include arbitrary code execution, privilege escalation, and denial of service.

    0000056
    607 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applibfuse_projectlibfuse---

Explore more