Answer in brief
CVE-2026-80855 records a Unknown severity vulnerability in fuse: fix invalidate lock leak on open O_TRUNC DAX failure. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=d58366aab86854217b81679d1a9dcd54a2edfc2a <1b04d80a27d317064cce2307472f5bef9975bc50 || >=2fdbb8dd01556e1501132b5ad3826e8f71e24a8b <a61524da59a2f5ac9c8de23ff98b30da769ab144 || >=2fdbb8dd01556e1501132b5ad3826e8f71e24a8b <dcf30a56624c2a0cfab1bada5b1ca8cc0c02f010 || >=2fdbb8dd01556e1501132b5ad3826e8f71e24a8b <7288c279ddbd654a06c82118c1a3f5570c1807f0 || >=2fdbb8dd01556e1501132b5ad3826e8f71e24a8b <776e85fda752f9a15e0f82dec42ecacd12a9bd94 || >=2fdbb8dd01556e1501132b5ad3826e8f71e24a8b <1d3e701cda2f41d48aa721b3ebefbe0fbf8d74da || >=2fdbb8dd01556e1501132b5ad3826e8f71e24a8b <e981474d7bf1457da12404e169ea147d2c8ecea7 || >=2fdbb8dd01556e1501132b5ad3826e8f71e24a8b <a927f1867e61b78f39f9da0bbba3c98c2ca151fe || 81775ab858b4236c52c5da7e25cec6e49dd91b46 || b57e150ac2eac791d5d187923b73dc2dafaf67fa || 1fdbbe246daf348adaa0739463384b16ceba1fc0 || >=5.15.109 <5.15.220 || >=5.10.179 <5.11 || >=5.18.18 <5.19 || >=5.19.2 <5.20 | 1b04d80a27d317064cce2307472f5bef9975bc50, a61524da59a2f5ac9c8de23ff98b30da769ab144, dcf30a56624c2a0cfab1bada5b1ca8cc0c02f010, 7288c279ddbd654a06c82118c1a3f5570c1807f0, 776e85fda752f9a15e0f82dec42ecacd12a9bd94, 1d3e701cda2f41d48aa721b3ebefbe0fbf8d74da, e981474d7bf1457da12404e169ea147d2c8ecea7, a927f1867e61b78f39f9da0bbba3c98c2ca151fe, 5.15.220, 5.11, 5.19, 5.20 |
| Linux/Linuxgeneric | 6.0 | Not reported |
Published upstream
Sep 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 4, 2026
In the Linux kernel, the following vulnerability has been resolved: fuse: fix invalidate lock leak on open O_TRUNC DAX failure fuse_open() takes filemap_invalidate_lock() for a DAX truncate (dax_truncate = true) and releases it before the out_inode_unlock label. But when fuse_dax_break_layouts() fails, the goto out_inode_unlock skips the unlock and leaks the rwsem, so any later fault or truncate on the file stalls on the stale lock. fuse_dax_break_layouts() can fail with -ERESTARTSYS when a signal interrupts the wait for busy DAX pages to drain: open("file", O_RDWR | O_TRUNC) └─ fuse_open() ├─ filemap_invalidate_lock() # dax_truncate └─ fuse_dax_break_layouts() └─ dax_break_layout() └─ wait_page_idle() # TASK_INTERRUPTIBLE └─ fuse_wait_dax_page() # unlock, schedule, re-lock └─ signal → -ERESTARTSYS goto out_inode_unlock # <- lock leaked Fix this by moving filemap_invalidate_unlock() below the label so that all error paths release the lock, and rename the label to out_unlock as it now covers more than just the inode lock.
Quoted source text, attributed separately from HOL analysis.