CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's FUSE (Filesystem in Userspace) implementation, specifically in the handling of io-uring queues. The issue arises from improper memory ordering during the initialization and publication of queue pointers, which can lead to race conditions and undefined behavior for concurrent readers. Organizations utilizing Linux systems with FUSE should prioritize this vulnerability to ensure the integrity and stability of their applications that rely on io-uring functionality.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: fuse: publish io-uring queues with release semantics fuse_uring_create_queue() initializes a fuse_ring_queue and then publishes the pointer into ring->queues[qid] with WRITE_ONCE() under the fch->lock. There are several readers that may concurrently be fetching that pointer locklessly and then deferencing it. WRITE_ONCE() doesn't ensure ordering of the queue's field initialization before the ring->queues[qid] pointer assignment. The queue must be published with smp_store_release() so the field initialization is guaranteed to happen before. Readers in paths where the read may happen concurrently with the store need to use READ_ONCE() because any race involving a plain access is undefined.