Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-64061

netfs: Fix early put of sink folio in netfs_read_gaps()
Back to all
CVE

CVE-2026-64061

netfs: Fix early put of sink folio in netfs_read_gaps()

In the Linux kernel, the following vulnerability has been resolved:

netfs: Fix early put of sink folio in netfsreadgaps()

Fix netfsreadgaps() to release the sink page it uses after waiting for

the request to complete.  The way the sink page is used is that an

ITER_BVEC-class iterator is created that has the gaps from the target folio

at either end, but has the sink page tiled over the middle so that a single

read op can fill in both gaps.

The bug was found by KASAN detecting a UAF on the generic/075 xfstest in

the cifsd kernel thread that handles reception of data from the TCP socket:

 BUG: KASAN: use-after-free in copyto_iter+0x48a/0xa20

 Write of size 885 at addr ffff888107f92000 by task cifsd/1285

 CPU: 2 UID: 0 PID: 1285 Comm: cifsd Not tainted 7.0.0 #6 PREEMPT(lazy)

 Call Trace:

  dumpstacklvl+0x5d/0x80

  print_report+0x17f/0x4f1

  kasan_report+0x100/0x1e0

  kasancheckrange+0x10f/0x1e0

  _asanmemcpy+0x3c/0x60

  copyto_iter+0x48a/0xa20

  _skbdatagram_iter+0x2c9/0x430

  skbcopydatagram_iter+0x6e/0x160

  tcprecvmsglocked+0xce0/0x1130

  tcp_recvmsg+0xeb/0x300

  inet_recvmsg+0xcf/0x3a0

  sock_recvmsg+0xea/0x100

  cifsreadvfrom_socket+0x3a6/0x4d0 [cifs]

  cifsreaditerfromsocket+0xdd/0x130 [cifs]

  cifsreadvreceive+0xaad/0xb10 [cifs]

  cifsdemultiplexthread+0x1148/0x1740 [cifs]

  kthread+0x1cf/0x210

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/2a39d49c8d97df8cb8fa80c10859bc1ba7358c6b, https://git.kernel.org/stable/c/3e5dd91b87a8b1450217b56a336bee315f40da7d, https://git.kernel.org/stable/c/412e8bad48967fd34295866636c028befd27d8b9, https://git.kernel.org/stable/c/d4f4bc87c76511cf2532448b0fa40c25e894bd7d, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64061.json, https://nvd.nist.gov/vuln/detail/CVE-2026-64061, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00469%
EPSS Percentile
0.38854%
Introduced Version
ee4cdf7ba857a894ad1650d6ab77669cbbfa329e,6.12.0,6.13.0,6.19.0,0
Fix Available
3e5dd91b87a8b1450217b56a336bee315f40da7d,6.12.92,6.18.34,7.0.11,6.12.94-1,7.0.0-28.28~24.04.1,7.0.0-1016.16~24.04.1,7.0.0-28.28.1~24.04.3,1:6.18.35-68.127.amzn2023,1:1.0-0.amzn2023,1:6.12.92-122.166.amzn2023

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading