Junglewise Threat Intelligence

CVE-2026-64065: Linux Kernel denial of service in netfs_write_begin

CVE-2026-64065 · Severity: info · CVSS 5.5 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A stability issue was identified in the Linux kernel's network filesystem (netfs) component. Under specific conditions during file write operations, the system may encounter a kernel crash (BUG), leading to a denial of service. This primarily affects systems using network-backed storage like Ceph.

Technical details

A vulnerability exists in the Linux kernel's netfs subsystem within the netfs_write_begin() function. The issue is characterized by a VM_BUG_ON_FOLIO() assertion failure occurring at mm/filemap.c:1504, specifically when folio_test_locked(folio) returns false during a folio_unlock operation. This indicates a synchronization or locking state inconsistency during write operations on network filesystems (observed with ceph_aops). An attacker with local access could potentially trigger this crash by performing specific file stress operations, resulting in a kernel panic (Oops) and system unavailability. Patches have been released across multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 7.0.0-rc1

Timeline

  • 2026-05-12: other: Patch authored
  • 2026-06-01: patched: Patch committed to stable tree
  • 2026-07-19: disclosed: CVE published

References

Related threats