A vulnerability was found in Linux Kernel up to 6.18.38/7.1.3 and classified as very critical. This affects the function fuse_uring_async_stop_queues of the component fuse-uring. Executing a manipulation of the argument queue_refs can lead to use after free.

The identification of this vulnerability is CVE-2026-64261. The attack may be launched remotely. There is no exploit available.

It is suggested to upgrade the affected component.