CVE-2026-64067
Last modified
CVE-2026-64067 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: netfs: Fix missing barriers when accessing stream->subrequests locklessly The list of subrequests attached to stream->subrequests is accessed without locks by netfs_collect_read_results() and netfs_collect_write_results(), and then they access subreq->flags without taking a barrier after getting the subreq pointer from the list. Relatedly, the functions that build the list don't use any sort of write barrier when constructing the list to make sure that the NETFS_SREQ_IN_PROGRESS flag is perceived to be set first if no lock is taken. Fix this by: (1) Add a new list_add_tail_release() function that uses a release barrier to set the pointer to the new member of the list. (2) Add a new list_first_entry_or_null_acquire() function that uses an acquire barrier to read the pointer to the first member in a list (or return NULL). (3) Use list_add_tail_release() when adding a subreq to ->subrequests. (4) Use list_first_entry_or_null_acquire() when initially accessing the front of the list (when an item is removed, the pointer to the new front iterm is obtained under the same lock).. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix missing barriers when accessing stream->subrequests locklessly The list of subrequests attached to stream->subrequests is accessed without locks by netfs_collect_read_results() and netfs_collect_write_results(), and then they access subreq->flags without taking a barrier after getting the subreq pointer from the list. Relatedly, the functions that build the list don't use any sort of write barrier when constructing the list to make sure that the NETFS_SREQ_IN_PROGRESS flag is perceived to be set first if no lock is taken. Fix this by: (1) Add a new list_add_tail_release() function that uses a release barrier to set the pointer to the new member of the list. (2) Add a new list_first_entry_or_null_acquire() function that uses an acquire barrier to read the pointer to the first member in a list (or return NULL). (3) Use list_add_tail_release() when adding a subreq to ->subrequests. (4) Use list_first_entry_or_null_acquire() when initially accessing the front of the list (when an item is removed, the pointer to the new front iterm is obtained under the same lock).
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 288ace2f57c9d06dd2e42bd80d03747d879a4068, < 293a4532c36f38458e38b8879b174ab797718b9d; >= 288ace2f57c9d06dd2e42bd80d03747d879a4068, < b5782e2d462c028096f922abca46318cec890670 |
| Linux | Linux | 6.10 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-64067?
How severe is CVE-2026-64067?
How do I fix CVE-2026-64067?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-64061In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-64062In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64063In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64064In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64065In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64066In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-64068In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-64069In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-64070In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64071In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64072In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64073In the Linux kernel, the following vulnerability has been re…7.8
Are you affected by CVE-2026-64067?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
