CVE-2026-64061
Received Received - Intake

Use-After-Free in Linux Kernel netfs

Vulnerability report for CVE-2026-64061, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-19

Last updated on: 2026-07-19

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix early put of sink folio in netfs_read_gaps() Fix netfs_read_gaps() to release the sink page it uses after waiting for the request to complete. The way the sink page is used is that an ITER_BVEC-class iterator is created that has the gaps from the target folio at either end, but has the sink page tiled over the middle so that a single read op can fill in both gaps. The bug was found by KASAN detecting a UAF on the generic/075 xfstest in the cifsd kernel thread that handles reception of data from the TCP socket: BUG: KASAN: use-after-free in _copy_to_iter+0x48a/0xa20 Write of size 885 at addr ffff888107f92000 by task cifsd/1285 CPU: 2 UID: 0 PID: 1285 Comm: cifsd Not tainted 7.0.0 #6 PREEMPT(lazy) Call Trace: dump_stack_lvl+0x5d/0x80 print_report+0x17f/0x4f1 kasan_report+0x100/0x1e0 kasan_check_range+0x10f/0x1e0 __asan_memcpy+0x3c/0x60 _copy_to_iter+0x48a/0xa20 __skb_datagram_iter+0x2c9/0x430 skb_copy_datagram_iter+0x6e/0x160 tcp_recvmsg_locked+0xce0/0x1130 tcp_recvmsg+0xeb/0x300 inet_recvmsg+0xcf/0x3a0 sock_recvmsg+0xea/0x100 cifs_readv_from_socket+0x3a6/0x4d0 [cifs] cifs_read_iter_from_socket+0xdd/0x130 [cifs] cifs_readv_receive+0xaad/0xb10 [cifs] cifs_demultiplex_thread+0x1148/0x1740 [cifs] kthread+0x1cf/0x210

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-19
Last Modified
2026-07-19
Generated
2026-07-20
AI Q&A
2026-07-19
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a use-after-free (UAF) bug in the netfs_read_gaps() function. The issue occurs when the sink page is released too early before the read request completes. An ITER_BVEC-class iterator is used with gaps in the target folio filled by a sink page, but the sink page is tiled incorrectly, leading to a UAF detected by KASAN during testing.

Detection Guidance

This vulnerability is specific to the Linux kernel's netfs subsystem and may not have direct detection commands. Monitor kernel logs for UAF errors or crashes in cifsd/kernel threads. Check for KASAN reports indicating use-after-free in _copy_to_iter or related functions.

Impact Analysis

This vulnerability could allow an attacker to cause a system crash or execute arbitrary code with kernel privileges. It specifically affects systems using the Linux kernel with CIFS/SMB file sharing enabled, potentially leading to data corruption or unauthorized access.

Compliance Impact

This vulnerability is a use-after-free bug in the Linux kernel's netfs subsystem, specifically in netfs_read_gaps(). It could potentially lead to memory corruption or crashes in kernel threads handling network file system operations, such as cifsd. While the description does not explicitly mention data exposure or integrity issues, such memory corruption vulnerabilities may compromise system stability and could indirectly affect compliance with standards like GDPR or HIPAA by increasing the risk of data breaches or unauthorized access if exploited.

Mitigation Strategies

Apply the kernel patch fixing netfs_read_gaps() to prevent the UAF issue. Update to a patched kernel version where this bug is resolved. Restart services using the affected subsystem, such as cifsd, after applying the update.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-64061. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart