Executive brief
A vulnerability in the Linux kernel's network filesystem (netfs) component could cause system instability or data handling errors during file reading operations. The issue occurs when the system fails to pause the creation of new data requests after a previous request has already failed. This could potentially lead to resource exhaustion or unexpected behavior in applications relying on networked storage.
Technical details
A vulnerability was identified in the Linux kernel's netfs subsystem within the netfs_read_to_pagecache() function in fs/netfs/buffered_read.c. The function failed to check for the NETFS_RREQ_PAUSE or NETFS_RREQ_FAILED flags after issuing a read subrequest. This oversight allowed the kernel to continue generating new subrequests even after a prior subrequest had failed or requested a pause. An attacker or a failing network condition could exploit this to cause improper state handling during buffered reads. The fix introduces checks for these flags to ensure the request loop pauses or terminates correctly upon subrequest failure.
Affected products
- Linux Linux Kernel 6.12, 6.18.34, 7.0.11
Timeline
- 2026-05-12: patched: Initial fix commit by David Howells
- 2026-07-19: disclosed: CVE published