Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-64069

netfs: Fix cancellation of a DIO and single read subrequests
Back to all
CVE

CVE-2026-64069

netfs: Fix cancellation of a DIO and single read subrequests

In the Linux kernel, the following vulnerability has been resolved:

netfs: Fix cancellation of a DIO and single read subrequests

When the preparation of a new subrequest for a read fails, if the

subrequest has already been added to the stream->subrequests list, it can't

simply be put and abandoned as the collector may see it.  Also, if it

hasn't been queued yet, it has two outstanding refs that both need to be

put.  Both DIO read and single-read dispatch fail at this; further, both

differ in the order they do things to the way buffered read works.

Fix cancellation of both DIO-read and single-read subrequests that failed

preparation by the following steps:

 (1) Harmonise all three reads (buffered, dio, single) to queue the subreq

     before prepping it.

 (2) Make all three call netfsqueueread() to do the queuing.

 (3) Set NETFSRREQALL_QUEUED independently of the queuing as we don't

     know the length of the subreq at this point.

 (4) In all cases, set the error and NETFSSREQFAILED flag on the subreq

     and then call netfsreadsubreq_terminated() to deal with it.  This

     will pass responsibility off to the collector for dealing with it.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/5366199be46fb53de62861721d34ba816e7e440e, https://git.kernel.org/stable/c/6f0f7ac1915abc0d202f0eb4b003a6548a5ba60d, https://git.kernel.org/stable/c/f73372a4c6900d117f8e903fe10b62692f95e6c4, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64069.json, https://nvd.nist.gov/vuln/detail/CVE-2026-64069, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00442%
EPSS Percentile
0.36982%
Introduced Version
e2d46f2ec332533816417b60933954173f602121,6.14.0,6.19.0,0
Fix Available
6f0f7ac1915abc0d202f0eb4b003a6548a5ba60d,6.18.34,7.0.11,7.0.0-28.28~24.04.1,7.0.0-1016.16~24.04.1,7.0.0-28.28.1~24.04.3,1:6.18.35-68.127.amzn2023,1:1.0-0.amzn2023

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading