Executive brief
A memory leak vulnerability was identified in the Linux kernel's network filesystem (netfs) component. This component is responsible for managing how the operating system interacts with files stored over a network. If an error occurs during a write operation, the system may fail to release certain internal resources, which could lead to gradual system performance degradation or instability over time.
Technical details
A reference count leak exists in the netfs subsystem of the Linux kernel. Specifically, in the netfs_write_begin() function within fs/netfs/buffered_read.c, the kernel fails to decrement the reference count on a request object (rreq) if netfs_wait_for_read() returns an error. An attacker or a series of legitimate but failing network operations could trigger this path, leading to a kernel memory leak. The fix moves the netfs_put_request() call to ensure it executes regardless of whether the read wait operation succeeded or failed. This issue affects kernels from version 5.18 up to the patched releases in the 6.18.x and 7.0.x branches.
Affected products
- Linux Linux Kernel 5.18 to 6.18.34, 7.0.11
Timeline
- 2026-05-12: disclosed: Initial patch submitted by David Howells
- 2026-07-19: advisory: CVE published in NVD dataset