๐Ÿ” CVE Alert

CVE-2026-64216

UNKNOWN 0.0

netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages() netfs_unlock_abandoned_read_pages(rreq) accesses the index of the folios it is wanting to unlock and compares that to rreq->no_unlock_folio so that it doesn't unlock a folio being read for netfs_perform_write() or netfs_write_begin(). However, given that netfs_unlock_abandoned_read_pages() is called _after_ NETFS_RREQ_IN_PROGRESS is cleared, the one folio that it's not allowed to dereference is the one specified by ->no_unlock_folio as ownership immediately reverts to the caller. Fix this by storing the folio pointer instead and using that rather than the index. Also fix netfs_unlock_read_folio() where the same applies.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 24, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
ee4cdf7ba857a894ad1650d6ab77669cbbfa329e < 6080fa3ecfbb4448a3b47368629534c09b6ec750 ee4cdf7ba857a894ad1650d6ab77669cbbfa329e < 3866d015f33aeedf81338dd99154703bef33faef ee4cdf7ba857a894ad1650d6ab77669cbbfa329e < dbe556972100fabb8e5a1b3d2163831ff07b1e8e
Linux / Linux
6.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/6080fa3ecfbb4448a3b47368629534c09b6ec750 git.kernel.org: https://git.kernel.org/stable/c/3866d015f33aeedf81338dd99154703bef33faef git.kernel.org: https://git.kernel.org/stable/c/dbe556972100fabb8e5a1b3d2163831ff07b1e8e