CVE-2026-33179 is a NULL pointer dereference and memory leak vulnerability affecting libfuse versions 3.18.0 through 3.18.1, specifically within its io_uring transport, allowing a local attacker to crash the FUSE daemon or cause resource exhaustion. Rated Medium (CVSS 5.5), it requires local access with low attack complexity, leading to a high impact on system availability. There are no known public exploits or active exploitation, though the vulnerability has received some community discussion and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.18.0, < 3.18.2CPE matchmatch criteria | cpe:2.3:a:libfuse_project:libfuse:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.