Executive brief
A vulnerability in the Linux kernel's network file system (netfs) component could allow a local user to cause a system crash. The issue occurs when certain file write operations fail, leading the system to incorrectly process memory and result in a 'kernel oops' or crash. This primarily affects systems using network-based storage or specific file-splicing operations.
Technical details
A vulnerability exists in the netfs unbuffered write error handling logic. When all subrequests in an unbuffered write stream fail, the 'stream->transferred' value is not updated and retains its initial LONG_MAX value. This causes 'write_iter()' to return an incorrect, extremely large value instead of an error code. Subsequent calls to 'iter_file_splice_write()' attempt to clean up pipe buffers based on this large value, leading to an out-of-bounds access and a NULL pointer dereference. The fix introduces a validity flag for the transferred value and initializes the counter to zero. Patches are available in stable kernel releases 6.12.44 and 6.16.4.
Affected products
- Linux Linux Kernel 6.10 to 6.12.43, 6.13 to 6.16.3
Timeline
- 2025-08-14: patched: Initial fix authored by David Howells
- 2025-09-05: disclosed: CVE published