Executive brief
A vulnerability was identified in the Linux kernel's network filesystem (netfs) component, which manages how the operating system interacts with files stored over a network. Under specific conditions involving file truncation and memory mapping, the system can experience a kernel crash (oops). This could lead to a local denial-of-service, causing the system to stop responding or restart unexpectedly, potentially disrupting business operations or active services.
Technical details
A vulnerability exists in the Linux kernel's netfs subsystem within the `netfs_invalidate_folio()` function. When a streaming write creates a dirty folio and the file is subsequently truncated to remove that dirty data, the `netfs_folio` structure is discarded but the dirty flag remains set. If the folio is later accessed via `mmap()`, `netfs_read_folio()` incorrectly identifies the page as dirty and attempts to call `netfs_read_gaps()`. Because `netfs_read_gaps()` expects a `netfs_folio` structure that no longer exists, it triggers a kernel oops. The fix involves calling `folio_cancel_dirty()` in `netfs_invalidate_folio()` when all dirty data is erased. This issue affects systems using netfs with fscaching disabled or specific O_RDWR configurations.
Affected products
- Linux Linux Kernel 9ebff83e6481 to 31ba145faceb378fa01afcb8349e15ea7d95e542
Timeline
- 2026-05-12: patched: Initial fix committed to mainline kernel
- 2026-07-19: disclosed: CVE published