CVE-2026-64158
Last modified
CVE-2026-64158 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: netfs: Fix write streaming disablement if fd open O_RDWR In netfs_perform_write(), "write streaming" (the caching of dirty data in dirty but !uptodate folios) is performed to avoid the need to read data that is just going to get immediately overwritten. However, this is/will be disabled in three circumstances: if the fd is open O_RDWR, if fscache is in use (as we need to round out the blocks for DIO) or if content encryption is enabled (again for rounding out purposes). The idea behind disabling it if the fd is open O_RDWR is that we'd need to flush the write-streaming page before we could read the data, particularly through mmap. EPSS estimates a 0.08% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix write streaming disablement if fd open O_RDWR In netfs_perform_write(), "write streaming" (the caching of dirty data in dirty but !uptodate folios) is performed to avoid the need to read data that is just going to get immediately overwritten. However, this is/will be disabled in three circumstances: if the fd is open O_RDWR, if fscache is in use (as we need to round out the blocks for DIO) or if content encryption is enabled (again for rounding out purposes). The idea behind disabling it if the fd is open O_RDWR is that we'd need to flush the write-streaming page before we could read the data, particularly through mmap. But netfs now fills in the gaps if ->read_folio() is called on the page, so that is unnecessary. Further, this doesn't actually work if a separate fd is open for reading. Fix this by removing the check for O_RDWR, thereby allowing streaming writes even when we might read. This caused a number of problems with the generic/522 xfstest, but those are now fixed.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= c38f4e96e605f17990e871214e6ea1496bc4e65f, < 9adf8e47d73d5e3c2fe77dea649dcde350ccd65c; >= c38f4e96e605f17990e871214e6ea1496bc4e65f, < 616578e40dcba3f94810d841c5a52b7e3bc8ede7; >= c38f4e96e605f17990e871214e6ea1496bc4e65f, < 7a9fa5b020a3a40f8291a71cd44c08d931da430d; >= c38f4e96e605f17990e871214e6ea1496bc4e65f, < 70a7b9193bbbfceaab5974de66834c64ccc875dd |
| Linux | Linux | 6.8 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-64158?
How severe is CVE-2026-64158?
How do I fix CVE-2026-64158?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-64152In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64153In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-64154In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64155In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64156In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64157In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64159In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6416Tanium addressed an uncontrolled resource consumption vulner…4.9
- CVE-2026-64160In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-64161In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64162In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-64163In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-64158?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
