CVE-2026-64063
In the Linux kernel, the following vulnerability has been resolved:
netfs: Fix streaming write being overwritten
In order to avoid reading whilst writing, netfslib will allow "streaming writes" in which dirty data is stored directly into folios without reading them first. Such folios are marked dirty but may not be marked uptodate. If a folio is entirely written by a streaming write, uptodate will be set, otherwise it will have a netfs_folio struct attached to ->private recording the dirty region.
In the event that a partially written streaming write page is to be overwritten entirely by a single write(), netfs_perform_write() will try to copy over it, but doesn't discard the netfs_folio if it succeeds; further, it doesn't correctly handle a partial copy that overwrites some of the dirty data.
Leer descripción completaMostrar menos
Fix this by the following:
Found with:
using the following as junk.fsxops:
on cifs with the default cache option.
It shows folio 0x24 misbehaving if the FMODE_READ check is commented out in netfs_perform_write():
and no fscache. This was initially found with the generic/522 xfstest.
Detalles técnicos trazas, registros y código del informe original
(1) If the folio is successfully overwritten, free the netfs_folio struct
before marking the page uptodate.
(2) If the copy to the folio partially fails, but short of the dirty data,
just ignore the copy.
(3) If the copy partially fails and overwrites some of the dirty data,
accept the copy, update the netfs_folio struct to record the new data.
If the folio is now filled, free the netfs_folio and set uptodate,
otherwise return a partial write.
fsx -q -N 1000000 -p 10000 -o 128000 -l 600000 \
/xfstest.test/junk --replay-ops=junk.fsxops
truncate 0x0 0 0x927c0
write 0x63fb8 0x53c8 0
copy_range 0xb704 0x19b9 0x24429 0x79380
write 0x2402b 0x144a2 0x90660 *
write 0x204d5 0x140a0 0x927c0 *
copy_range 0x1f72c 0x137d0 0x7a906 0x927c0 *
read 0x00000 0x20000 0x9157c
read 0x20000 0x20000 0x9157c
read 0x40000 0x20000 0x9157c
read 0x60000 0x20000 0x9157c
read 0x7e1a0 0xcfb9 0x9157c
if (//(file->f_mode & FMODE_READ) ||
netfs_is_cache_enabled(ctx)) {CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation75 % - Impacto principal
T1565.001Stored Data Manipulationimpact80 % - Impacto secundario
T1499.004Application or System Exploitationimpact60 %
Vulnerabilidad local (AV:L/PR:L) en kernel que permite escribir memoria sin validación (CWE-787 buffer overflow), causando corrupción de datos de folio. Escalada de privilegios posible mediante manipulación de estructuras en memoria.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-787
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-64063",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "8f52de0077ba3bf41e5d53d67a185700f41efce7",
"lessThan": "20195925c768626dc901a4781a51e508702c88ad",
"versionType": "git"
},
{
"status": "affected",
"version": "8f52de0077ba3bf41e5d53d67a185700f41efce7",
"lessThan": "ef9b521212e4863814ef7dfe19889abaf55ca840",
"versionType": "git"
},
{
"status": "affected",
"version": "8f52de0077ba3bf41e5d53d67a185700f41efce7",
"lessThan": "cdae00e8e215d95911d95f100599e187b6560de5",
"versionType": "git"
},
{
"status": "affected",
"version": "8f52de0077ba3bf41e5d53d67a185700f41efce7",
"lessThan": "7b4dcf1b9455a6e52ac7478b4057dbe10359576d",
"versionType": "git"
}
],
"programFiles": [
"fs/netfs/buffered_write.c",
"include/trace/events/netfs.h"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.12"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.12",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.92",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver",
"lessThanOrEqual": "7.0.*"
},
{
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/netfs/buffered_write.c",
"include/trace/events/netfs.h"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-07-19T16:17:46.820",
"references": [
{
"url": "https://git.kernel.org/stable/c/20195925c768626dc901a4781a51e508702c88ad",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7b4dcf1b9455a6e52ac7478b4057dbe10359576d",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/cdae00e8e215d95911d95f100599e187b6560de5",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ef9b521212e4863814ef7dfe19889abaf55ca840",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-787"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix streaming write being overwritten\n\nIn order to avoid reading whilst writing, netfslib will allow \"streaming\nwrites\" in which dirty data is stored directly into folios without reading\nthem first. Such folios are marked dirty but may not be marked uptodate.\nIf a folio is entirely written by a streaming write, uptodate will be set,\notherwise it will have a netfs_folio struct attached to ->private recording\nthe dirty region.\n\nIn the event that a partially written streaming write page is to be\noverwritten entirely by a single write(), netfs_perform_write() will try to\ncopy over it, but doesn't discard the netfs_folio if it succeeds; further,\nit doesn't correctly handle a partial copy that overwrites some of the\ndirty data.\n\nFix this by the following:\n\n (1) If the folio is successfully overwritten, free the netfs_folio struct\n before marking the page uptodate.\n\n (2) If the copy to the folio partially fails, but short of the dirty data,\n just ignore the copy.\n\n (3) If the copy partially fails and overwrites some of the dirty data,\n accept the copy, update the netfs_folio struct to record the new data.\n If the folio is now filled, free the netfs_folio and set uptodate,\n otherwise return a partial write.\n\nFound with:\n\n\tfsx -q -N 1000000 -p 10000 -o 128000 -l 600000 \\\n\t /xfstest.test/junk --replay-ops=junk.fsxops\n\nusing the following as junk.fsxops:\n\n\ttruncate 0x0 0 0x927c0\n\twrite 0x63fb8 0x53c8 0\n\tcopy_range 0xb704 0x19b9 0x24429 0x79380\n\twrite 0x2402b 0x144a2 0x90660 *\n\twrite 0x204d5 0x140a0 0x927c0 *\n\tcopy_range 0x1f72c 0x137d0 0x7a906 0x927c0 *\n\tread 0x00000 0x20000 0x9157c\n\tread 0x20000 0x20000 0x9157c\n\tread 0x40000 0x20000 0x9157c\n\tread 0x60000 0x20000 0x9157c\n\tread 0x7e1a0 0xcfb9 0x9157c\n\non cifs with the default cache option.\n\nIt shows folio 0x24 misbehaving if the FMODE_READ check is commented out in\nnetfs_perform_write():\n\n\t\tif (//(file->f_mode & FMODE_READ) ||\n\t\t netfs_is_cache_enabled(ctx)) {\n\nand no fscache. This was initially found with the generic/522 xfstest."
}
],
"lastModified": "2026-09-02T21:12:07.367",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9574AA5E-61DC-4F38-82BC-69F89AA7593C",
"versionEndExcluding": "6.12.92",
"versionStartIncluding": "6.12"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A4B1EF6D-18D7-4838-BC37-7499D5DCC3C0",
"versionEndExcluding": "6.18.34",
"versionStartIncluding": "6.13"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0520D091-FC52-4A50-AF07-70AE7D08B750",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "6.19"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B1EF7059-E670-45F4-B422-54C40FA86390"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0D38F0BF-A728-4133-A358-D44A2F7EE6D6"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EC732D08-5F7B-46D9-B154-E60C7F4F0A97"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E5910A9D-F60A-409A-B486-FE66BFEBA9B9"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}