{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-64067","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T07:54:57.030Z","datePublished":"2026-07-19T15:39:44.660Z","dateUpdated":"2026-08-05T12:38:51.145Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:38:51.145Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix missing barriers when accessing stream->subrequests locklessly\n\nThe list of subrequests attached to stream->subrequests is accessed without\nlocks by netfs_collect_read_results() and netfs_collect_write_results(),\nand then they access subreq->flags without taking a barrier after getting\nthe subreq pointer from the list.  Relatedly, the functions that build the\nlist don't use any sort of write barrier when constructing the list to make\nsure that the NETFS_SREQ_IN_PROGRESS flag is perceived to be set first if\nno lock is taken.\n\nFix this by:\n\n (1) Add a new list_add_tail_release() function that uses a release barrier\n     to set the pointer to the new member of the list.\n\n (2) Add a new list_first_entry_or_null_acquire() function that uses an\n     acquire barrier to read the pointer to the first member in a list (or\n     return NULL).\n\n (3) Use list_add_tail_release() when adding a subreq to ->subrequests.\n\n (4) Use list_first_entry_or_null_acquire() when initially accessing the\n     front of the list (when an item is removed, the pointer to the new\n     front iterm is obtained under the same lock)."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - The bug is in the netfs client library used by CIFS/SMB, Ceph, 9p, AFS, and NFS clients; a remote file server controls when read/write completions arrive over the network and can time responses to hit the lockless subrequest list race during collection.\nAC:L - The attacker controls both sides of the concurrency (issuing concurrent reads/writes and timing remote completions); on weakly-ordered architectures the missing barriers can cause deterministic misordering without relying on rare external conditions.\nPR:N - A malicious or compromised remote SMB/Ceph/NFS server needs no local privileges on the victim; exploitation only requires the victim system to perform I/O against an already-mounted network filesystem share.\nUI:N - On servers and enterprise systems with persistent fstab/autofs mounts, automated processes (writeback, readahead, backup daemons) trigger netfs I/O without live end-user action at exploit time.\nS:U - Impact is kernel memory corruption and privilege escalation within the same kernel security boundary; this is not a VM escape or cross-authority boundary bypass.\nC:H - Premature removal and freeing of in-flight subrequests is a use-after-free; the collector may read freed `netfs_io_subrequest` memory and stale counters, enabling arbitrary kernel memory disclosure.\nI:H - The UAF and concurrent access to subrequest fields while I/O handlers still run can corrupt heap metadata and subrequest state, providing a path to arbitrary kernel writes or code execution.\nA:H - Freeing active subrequests while SMB/Ceph completion handlers still reference them can cause kernel oops, BUG, or panic from use-after-free and list corruption."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/netfs/buffered_read.c","fs/netfs/misc.c","fs/netfs/read_collect.c","fs/netfs/write_collect.c","fs/netfs/write_issue.c","include/linux/list.h"],"versions":[{"version":"288ace2f57c9d06dd2e42bd80d03747d879a4068","lessThan":"293a4532c36f38458e38b8879b174ab797718b9d","status":"affected","versionType":"git"},{"version":"288ace2f57c9d06dd2e42bd80d03747d879a4068","lessThan":"b5782e2d462c028096f922abca46318cec890670","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/netfs/buffered_read.c","fs/netfs/misc.c","fs/netfs/read_collect.c","fs/netfs/write_collect.c","fs/netfs/write_issue.c","include/linux/list.h"],"versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","status":"unaffected","versionType":"semver"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"7.0.11"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/293a4532c36f38458e38b8879b174ab797718b9d"},{"url":"https://git.kernel.org/stable/c/b5782e2d462c028096f922abca46318cec890670"}],"title":"netfs: Fix missing barriers when accessing stream->subrequests locklessly","x_generator":{"engine":"bippy-1.2.0"}}}}