Executive brief
The Linux kernel's network filesystem (netfs) layer contains a flaw in how it handles errors during page writeback operations. When an error occurs while writing cached file pages to disk, the error handling logic fails to properly clean up iteration state and unlock affected pages, potentially causing memory leaks, hung processes, or system instability. This can be triggered by legitimate I/O failures and lead to service degradation or system hangs.
Technical details
The vulnerability is a logic error in the writeback_iter() loop within fs/netfs/write_issue.c. When netfs_write_folio() returns a negative error code, the original code breaks out of the loop without calling writeback_iter() again with the error parameter set, which prevents proper cleanup of iteration state. Additionally, the current folio is not unlocked or redirtied, leaving resources in an inconsistent state. The fix ensures that on error conditions (especially -ENOMEM), writeback_iter() is called with the error set to allow state cleanup, and the folio is properly redirtied and unlocked before returning. This is a local kernel bug requiring no network access or privilege escalation; it affects any system performing writeback operations under error conditions.
Affected products
- Linux Linux kernel Affected versions prior to patch (netfs module affected in v5.18+)
Timeline
- 2026-08-15: disclosed
- 2026-06-25: patched: Upstream fix committed by David Howells