Executive brief
A vulnerability was identified in the Linux kernel's network filesystem (netfs) library, which handles data transfers between the kernel and network-backed storage. A technical error in how the system manages memory 'folios' during read operations could lead to a 'use-after-free' condition, potentially causing system instability or crashes. This issue primarily affects system reliability and could be exploited to disrupt operations on affected Linux servers.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel's netfs library within the netfs_unlock_abandoned_read_pages() and netfs_unlock_read_folio() functions. The root cause is that the code attempts to access and compare the index of a folio after the NETFS_RREQ_IN_PROGRESS flag is cleared, at which point ownership of the folio may have already reverted to the caller. An attacker with local access could potentially trigger this race condition during buffered read or write-begin operations. The fix involves storing a direct folio pointer for comparison instead of relying on the folio index, ensuring safe dereferencing. Patches have been released for various stable kernel branches including 6.18.x and 7.0.x.
Affected products
- Linux Linux Kernel 6.12, 6.18.34, 7.0.11
Timeline
- 2026-07-24: advisory: CVE published by NVD
- 2026-06-01: patched: Fix committed to stable kernel trees