Junglewise Threat Intelligence

CVE-2026-64067: Linux Kernel race condition in netfs subrequest handling

CVE-2026-64067 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's network filesystem (netfs) library, which handles data transfers between the system and network storage. Due to a technical error in how the system tracks background data requests, it was possible for the system to misread the status of a file transfer. This could lead to unpredictable system behavior or data corruption during network file operations.

Technical details

A race condition exists in the Linux kernel netfs subsystem due to missing memory barriers in netfs_collect_read_results() and netfs_collect_write_results(). These functions access stream->subrequests locklessly but fail to use acquire/release semantics when retrieving subrequest pointers and checking the NETFS_SREQ_IN_PROGRESS flag. This can result in a CPU perceiving a subrequest pointer before the associated 'in progress' flag is correctly set, leading to inconsistent state. The fix introduces list_add_tail_release() and list_first_entry_or_null_acquire() to ensure proper memory ordering.

Affected products

  • Linux Linux 6.10, 7.0.11

Timeline

  • 2026-07-19: disclosed
  • 2026-07-19: advisory

References