libfuse has fixed two memory-safety vulnerabilities in its io_uring transport path, both introduced in version 3.18.0 and remediated in 3.18.2. The flaws, tracked as CVE-2026-33150 and CVE-2026-33179, affect only the io_uring code path; the traditional /dev/fuse transport is not impacted. CVE-2026-33150 is a high-severity use-after-free that can allow a local user to crash a FUSE daemon and may enable arbitrary code execution, while CVE-2026-33179 is a moderate-severity bug involving a NULL pointer dereference and memory leak that can crash the daemon during allocation failure and leak NUMA memory.
Follow-up disclosure said the use-after-free can be triggered when pthread_create fails or when io_uring_queue_init_params fails, and noted that container resource limits such as cgroup pids.max and RLIMIT_NPROC can reliably force the pthread_create failure condition. The same writeup said CVE-2026-33179 actually comprises two separate sub-bugs: a NULL dereference on numa_alloc_local failure and an error-handling flaw that can leave the filesystem hung, but that these issues do not chain into the use-after-free in shipped code. The vulnerabilities were privately reported by Abhinav Agarwal, reviewed for remediation by Akshat Sinha, and addressed through a coordinated libfuse release followed by GitHub Security Advisories.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
A subsequent technical clarification explained that CVE-2026-33150 can be triggered by pthread_create failure or io_uring_queue_init_params failure, and that container limits such as cgroup pids.max and RLIMIT_NPROC can reliably induce the pthread_create failure. It also clarified that CVE-2026-33179 comprises two separate sub-bugs and does not chain into the use-after-free in shipped code.
GitHub Security Advisories for CVE-2026-33150 and CVE-2026-33179 were published after the coordinated release. A follow-up writeup dated the advisory publication to March 19, 2026.
An oss-sec post publicly disclosed CVE-2026-33150 and CVE-2026-33179, stating they affected libfuse's io_uring code path and were fixed in 3.18.2. The disclosure noted that local users could trigger daemon crashes and, for the use-after-free, potentially arbitrary code execution.
The libfuse project remediated both vulnerabilities in version 3.18.2 through a coordinated release. The fixes addressed a high-severity use-after-free that could crash a FUSE daemon or potentially enable code execution, and a moderate-severity NULL dereference/memory leak issue that could crash the daemon or hang the filesystem under certain failure conditions.
Abhinav Agarwal privately disclosed the two io_uring-related memory-safety issues to the libfuse maintainer, beginning a coordinated remediation process. Akshat Sinha later reviewed the fixes.
Two vulnerabilities affecting libfuse's io_uring transport path were introduced in version 3.18.0: CVE-2026-33150, a use-after-free, and CVE-2026-33179, involving a NULL dereference and memory leak/error-handling issues. The traditional /dev/fuse transport was not affected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.