Executive brief
A vulnerability was identified in the Linux kernel's network filesystem (netfs) component, which manages how data is read from and written to network-based storage. Under certain conditions, the system might fail to wait for data to finish saving before attempting to read it again, potentially leading to data corruption or system instability. This issue primarily affects the reliability of file operations on networked drives.
Technical details
A race condition exists in the netfs_read_folio() function within the Linux kernel's netfs library. The function failed to wait for an ongoing writeback to complete before checking the folio's dirty flag or accessing folio->private data. Because the collector can clean up folio->private before the writeback flag is cleared, this could lead to the kernel trusting stale or invalid state information. The fix introduces a call to folio_wait_writeback() to ensure synchronization. This is a local vulnerability that could lead to memory corruption or data integrity issues within the filesystem layer.
Affected products
- Linux Linux Kernel 6.12 to 6.18.34, 7.0.11
Timeline
- 2026-05-12: patched: Initial fix commit authored
- 2026-07-19: disclosed: CVE published