Open Source Security mailing list@oss_securityDisclosure
The note announces two libfuse memory‑safety CVEs (Use-After-Free and NULL pointer dereference), lists affected and fixed versions, and confirms a patch, with no PoC or exploitation details.
Gray Hats@the_yellow_fallPatch
Researchers discovered RCE and DoS vulnerabilities in libfuse’s io_uring transport affecting Kubernetes CSI drivers; patches have been released to mitigate the issue.
CSIRT Italia@csirt_itPoC
The post confirms a proof‑of‑concept for the two Libfuse CVEs is available, indicating potential arbitrary code execution, privilege escalation, and denial‑of‑service, but no exploit code or patches are mentioned.
kinneko@kinnekoDisclosure
The article announces critical libfuse io_uring vulnerabilities (CVE‑2026‑33150 and CVE‑2026‑33179) that could threaten Linux and Kubernetes infrastructure.
CVE@CVEnewDisclosure
The text announces CVE‑2026‑33150 as a use‑after‑free flaw in libfuse’s io_uring subsystem affecting versions 3.18.0 to 3.18.1.
Hephaestvs@Vulcanux_PoC
The tweet announces the availability of a Proof‑of‑Concept for CVE‑2026‑33150 and CVE‑2026‑33179 affecting libfuse, noting the vulnerabilities include arbitrary code execution, privilege escalation, and denial of service.