A vulnerability was found in Linux Kernel up to 6.12.95/6.18.38/7.1.3. It has been declared as very critical. This issue affects the function fuse_resend/fuse_remove_pending_req of the component FUSE. The manipulation of the argument intr_entry results in use after free.

This vulnerability is identified as CVE-2026-64265. The attack can be executed remotely. There is not any exploit available.

It is recommended to upgrade the affected component.