Executive brief
The Linux kernel's network filesystem (netfs) component has a race condition in how it synchronizes access to request lists during retry operations. An attacker could exploit this to cause a denial of service or potentially corrupt file system state by triggering improper list traversal when concurrent threads add new requests.
Technical details
The vulnerability is a memory barrier (barriering) race condition in the netfs read and write retry code paths (fs/netfs/read_retry.c and fs/netfs/write_retry.c). When walking the subrequest list during retry operations, the code failed to use proper synchronization primitives (smp_load_acquire) before reading subrequest pointers, allowing the walk to miss or incorrectly process subrequests concurrently added by application threads. This violates memory ordering guarantees and can lead to list corruption, use-after-free conditions, or denial of service. The fix replaces unsafe list_for_each_continue macros with explicit barrier-protected pointer reads using smp_load_acquire. Attack requires local file system access and the ability to trigger concurrent netfs operations.
Affected products
- Linux Linux kernel Linux 5.18 through 7.x (netfs component, introduced by commits ee4cdf7ba857 and 288ace2f57c9)
Timeline
- 2026-08-15: disclosed
- 2026-07-02: patched: Upstream fix committed by David Howells
- 2026-09-21: patched: Stable tree backport by Greg Kroah-Hartman