Debian Package Tracker
Register | Log in
Subscribe

fuse3

Filesystem in Userspace (3.x version)

Choose email to subscribe with

general
  • source: fuse3 (main)
  • version: 3.18.2-1
  • maintainer: Laszlo Boszormenyi (GCS) (DMD)
  • arch: all
  • std-ver: 4.7.2
  • VCS: unknown
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 3.10.3-2
  • oldstable: 3.14.0-4
  • stable: 3.17.2-3
  • testing: 3.18.1-1
  • unstable: 3.18.2-1
versioned links
  • 3.10.3-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.14.0-4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.17.2-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.18.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.18.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • fuse (10 bugs: 0, 8, 2, 0)
  • fuse3 (5 bugs: 0, 4, 1, 0)
  • fuse3-udeb
  • libfuse3-4
  • libfuse3-4-udeb
  • libfuse3-dev (1 bugs: 0, 1, 0, 0)
action needed
2 security issues in forky high

There are 2 open security issues in forky.

2 important issues:
  • CVE-2026-33150: libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a use-after-free vulnerability in the io_uring subsystem of libfuse allows a local attacker to crash FUSE filesystem processes and potentially execute arbitrary code. When io_uring thread creation fails due to resource exhaustion (e.g., cgroup pids.max), fuse_uring_start() frees the ring pool structure but stores the dangling pointer in the session state, leading to a use-after-free when the session shuts down. The trigger is reliable in containerized environments where cgroup pids.max limits naturally constrain thread creation. This issue has been patched in version 3.18.2.
  • CVE-2026-33179: libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a NULL pointer dereference and memory leak in fuse_uring_init_queue allows a local user to crash the FUSE daemon or cause resource exhaustion. When numa_alloc_local fails during io_uring queue entry setup, the code proceeds with NULL pointers. When fuse_uring_register_queue fails, NUMA allocations are leaked and the function incorrectly returns success. Only the io_uring transport is affected; the traditional /dev/fuse path is not affected. PoC confirmed with AddressSanitizer/LeakSanitizer. This issue has been patched in version 3.18.2.
Created: 2026-03-21 Last update: 2026-03-21 10:30
lintian reports 1 warning normal
Lintian reports 1 warning about this package. You should make the package lintian clean getting rid of them.
Created: 2026-03-21 Last update: 2026-03-21 18:32
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.3 instead of 4.7.2).
Created: 2025-12-23 Last update: 2026-03-21 13:00
testing migrations
  • excuses:
    • Migration status for fuse3 (3.18.1-1 to 3.18.2-1): Waiting for test results or another package, or too young (no action required now - check later)
    • Issues preventing migration:
    • ∙ ∙ Autopkgtest for borgbackup: arm64: Test triggered, i386: Test triggered, ppc64el: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for borgbackup2: amd64: Test triggered (failure will be ignored), arm64: Test triggered, i386: Test triggered, ppc64el: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for cryfs/1.0.3-1: amd64: Pass, arm64: Test triggered, i386: Test triggered, ppc64el: Test triggered, riscv64: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for disorderfs/0.6.2-1: amd64: Pass, arm64: Test triggered, i386: Test triggered, ppc64el: Test triggered, riscv64: No tests, superficial or marked flaky ♻, s390x: Test triggered
    • ∙ ∙ Autopkgtest for e2fsprogs/1.47.4-1: amd64: Pass, arm64: Test triggered, i386: Test triggered, ppc64el: Test triggered, riscv64: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for flatpak/1.16.3-1: amd64: Pass, arm64: Test triggered, i386: Test triggered, ppc64el: Test triggered, riscv64: No tests, superficial or marked flaky ♻ (reference ♻), s390x: Test triggered
    • ∙ ∙ Autopkgtest for flatpak-builder/1.4.7-1: amd64: Pass, arm64: Test triggered, i386: Test triggered, ppc64el: Test triggered, riscv64: No tests, superficial or marked flaky ♻, s390x: Test triggered
    • ∙ ∙ Autopkgtest for fuseiso/20070708-8: amd64: Pass, arm64: Test triggered, i386: Test triggered, ppc64el: Test triggered, riscv64: No tests, superficial or marked flaky ♻, s390x: Test triggered
    • ∙ ∙ Autopkgtest for gvfs/1.60.0-1: amd64: Pass, arm64: Test triggered, i386: Test triggered, ppc64el: Test triggered, riscv64: No tests, superficial or marked flaky ♻, s390x: Test triggered
    • ∙ ∙ Autopkgtest for squashfuse/0.5.2-0.3: amd64: Pass, arm64: Test triggered, i386: Test triggered, ppc64el: Test triggered, riscv64: No tests, superficial or marked flaky ♻, s390x: Test triggered
    • ∙ ∙ Autopkgtest for xdg-desktop-portal/1.20.3+ds-3: amd64: Pass, arm64: Test triggered, i386: Test triggered, ppc64el: Test triggered, riscv64: No tests, superficial or marked flaky ♻, s390x: Test triggered
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/f/fuse3.html
    • ∙ ∙ Reproduced on amd64
    • ∙ ∙ Reproduced on arm64
    • ∙ ∙ Reproduced on armhf
    • ∙ ∙ Reproduced on i386
    • ∙ ∙ Reproducibility check waiting for results on ppc64el
    • ∙ ∙ 2 days old (needed 2 days)
    • Not considered
news
[rss feed]
  • [2026-03-21] Accepted fuse3 3.18.2-1 (source) into unstable (Laszlo Boszormenyi (GCS)) (signed by: Laszlo Boszormenyi)
  • [2025-12-30] fuse3 3.18.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-12-21] Accepted fuse3 3.18.1-1 (source) into unstable (Laszlo Boszormenyi (GCS)) (signed by: Laszlo Boszormenyi)
  • [2025-08-26] fuse3 3.17.4-1 MIGRATED to testing (Debian testing watch)
  • [2025-08-20] Accepted fuse3 3.17.4-1 (source) into unstable (Laszlo Boszormenyi (GCS)) (signed by: Laszlo Boszormenyi)
  • [2025-08-16] Accepted fuse3 3.17.3-1 (source) into unstable (Laszlo Boszormenyi (GCS)) (signed by: Laszlo Boszormenyi)
  • [2025-07-22] fuse3 3.17.2-3 MIGRATED to testing (Debian testing watch)
  • [2025-07-17] Accepted fuse3 3.17.2-3 (source) into unstable (Laszlo Boszormenyi (GCS)) (signed by: Laszlo Boszormenyi)
  • [2025-06-01] fuse3 3.17.2-2 MIGRATED to testing (Debian testing watch)
  • [2025-05-26] Accepted fuse3 3.17.2-2 (source) into unstable (Laszlo Boszormenyi (GCS)) (signed by: Laszlo Boszormenyi)
  • [2025-05-12] fuse3 3.17.2-1 MIGRATED to testing (Debian testing watch)
  • [2025-05-08] Accepted fuse3 3.17.2-1 (source) into unstable (Laszlo Boszormenyi (GCS)) (signed by: Laszlo Boszormenyi)
  • [2025-04-27] fuse3 3.17.1+git250416-1 MIGRATED to testing (Debian testing watch)
  • [2025-04-16] Accepted fuse3 3.17.1+git250416-1 (source) into unstable (Laszlo Boszormenyi (GCS)) (signed by: Laszlo Boszormenyi)
  • [2025-03-24] Accepted fuse3 3.17.1-1 (source) into unstable (Laszlo Boszormenyi (GCS)) (signed by: Laszlo Boszormenyi)
  • [2025-03-23] fuse3 3.17.1~rc1-3 MIGRATED to testing (Debian testing watch)
  • [2025-03-13] Accepted fuse3 3.17.1~rc1-3 (source) into unstable (Laszlo Boszormenyi (GCS)) (signed by: Laszlo Boszormenyi)
  • [2025-02-22] Accepted fuse3 3.17.1~rc1-2 (source) into experimental (Laszlo Boszormenyi (GCS)) (signed by: Laszlo Boszormenyi)
  • [2025-02-19] Accepted fuse3 3.17.1~rc1-1 (source) into experimental (Laszlo Boszormenyi (GCS)) (signed by: Laszlo Boszormenyi)
  • [2025-02-15] Accepted fuse3 3.17.1~rc0-1 (source amd64 all) into experimental (Debian FTP Masters) (signed by: Laszlo Boszormenyi)
  • [2024-09-27] fuse3 3.14.0-10 MIGRATED to testing (Debian testing watch)
  • [2024-09-21] Accepted fuse3 3.14.0-10 (source) into unstable (Laszlo Boszormenyi (GCS)) (signed by: Laszlo Boszormenyi)
  • [2024-09-15] Accepted fuse3 3.14.0-9 (source) into unstable (Laszlo Boszormenyi (GCS)) (signed by: Laszlo Boszormenyi)
  • [2024-09-13] Accepted fuse3 3.14.0-8 (source) into unstable (Laszlo Boszormenyi (GCS)) (signed by: Laszlo Boszormenyi)
  • [2024-08-31] fuse3 3.14.0-7 MIGRATED to testing (Debian testing watch)
  • [2024-08-25] Accepted fuse3 3.14.0-7 (source) into unstable (Laszlo Boszormenyi (GCS)) (signed by: Laszlo Boszormenyi)
  • [2024-07-12] fuse3 3.14.0-6 MIGRATED to testing (Debian testing watch)
  • [2024-07-07] Accepted fuse3 3.14.0-6 (source) into unstable (Laszlo Boszormenyi (GCS)) (signed by: Laszlo Boszormenyi)
  • [2024-04-10] Removed 3.14.0-5.1~exp1 from experimental (Debian FTP Masters)
  • [2024-01-31] Accepted fuse3 3.14.0-5.1~exp1 (source) into experimental (Lukas Märdian)
  • 1
  • 2
bugs [bug history graph]
  • all: 16 17
  • RC: 0
  • I&N: 12 13
  • M&W: 4
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (0, 1)
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 3.18.1-1
  • 2 bugs

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing