PT-2026-61378 · Linux · Linux

CVE-2026-64061

·

Published

2026-07-19

·

Updated

2026-07-19

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the Linux kernel, the following vulnerability has been resolved:
netfs: Fix early put of sink folio in netfs read gaps()
Fix netfs read gaps() to release the sink page it uses after waiting for the request to complete. The way the sink page is used is that an ITER BVEC-class iterator is created that has the gaps from the target folio at either end, but has the sink page tiled over the middle so that a single read op can fill in both gaps.
The bug was found by KASAN detecting a UAF on the generic/075 xfstest in the cifsd kernel thread that handles reception of data from the TCP socket:
BUG: KASAN: use-after-free in copy to iter+0x48a/0xa20 Write of size 885 at addr ffff888107f92000 by task cifsd/1285 CPU: 2 UID: 0 PID: 1285 Comm: cifsd Not tainted 7.0.0 #6 PREEMPT(lazy) Call Trace: dump stack lvl+0x5d/0x80 print report+0x17f/0x4f1 kasan report+0x100/0x1e0 kasan check range+0x10f/0x1e0 asan memcpy+0x3c/0x60 copy to iter+0x48a/0xa20 skb datagram iter+0x2c9/0x430 skb copy datagram iter+0x6e/0x160 tcp recvmsg locked+0xce0/0x1130 tcp recvmsg+0xeb/0x300 inet recvmsg+0xcf/0x3a0 sock recvmsg+0xea/0x100 cifs readv from socket+0x3a6/0x4d0 [cifs] cifs read iter from socket+0xdd/0x130 [cifs] cifs readv receive+0xaad/0xb10 [cifs] cifs demultiplex thread+0x1148/0x1740 [cifs] kthread+0x1cf/0x210

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-64061

Affected Products

Linux