Executive brief
A vulnerability was identified in the Linux kernel's network filesystem (netfs) component, which manages how data is read from network-based storage. A flaw in memory management could allow the system to attempt to use memory that has already been released, potentially leading to a system crash or unpredictable behavior. This issue primarily affects systems using network-attached storage protocols like CIFS/SMB.
Technical details
A use-after-free (UAF) vulnerability exists in the netfs_read_gaps() function within the Linux kernel's netfs subsystem. The root cause is an early call to folio_put() for a 'sink' page before the associated read request has completed. When the cifsd kernel thread or other network filesystem processes attempt to copy data into this already-released memory via _copy_to_iter, a UAF occurs. This was specifically observed during CIFS/SMB data reception. The fix involves reordering the code to ensure the sink folio is only released after netfs_wait_for_read() returns. Patches have been released for multiple stable kernel branches including 6.12.y, 6.18.y, and 7.0.y.
Affected products
- Linux Linux Kernel 6.12, 6.18, 7.0
Timeline
- 2026-05-12: patched: Initial fix authored by David Howells
- 2026-07-19: disclosed: CVE published to NVD dataset