CVE-2026-64061·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix early put of sink folio in netfs_read_gaps() Fix netfs_read_gaps() to release the sink page it uses after waiting for the request to complete. The way the sink page is used is that an ITER_BVEC-class iterator is created that has the gaps from the target folio at either end, but has the sink page tiled over the middle so that a single read op can fill in both gaps. The bug was found by KASAN detecting a UAF on the generic/075 xfstest in the cifsd kernel thread that handles reception of data from the TCP socket: BUG: KASAN: use-after-free in _copy_to_iter+0x48a/0xa20 Write of size 885 at addr ffff888107f92000 by task cifsd/1285 CPU: 2 UID: 0 PID: 1285 Comm: cifsd Not tainted 7.0.0 #6 PREEMPT(lazy) Call Trace: dump_stack_lvl+0x5d/0x80 print_report+0x17f/0x4f1 kasan_report+0x100/0x1e0 kasan_check_range+0x10f/0x1e0 __asan_memcpy+0x3c/0x60 _copy_to_iter+0x48a/0xa20 __skb_datagram_iter+0x2c9/0x430 skb_copy_datagram_iter+0x6e/0x160 tcp_recvmsg_locked+0xce0/0x1130 tcp_recvmsg+0xeb/0x300 inet_recvmsg+0xcf/0x3a0 sock_recvmsg+0xea/0x100 cifs_readv_from_socket+0x3a6/0x4d0 [cifs] cifs_read_iter_from_socket+0xdd/0x130 [cifs] cifs_readv_receive+0xaad/0xb10 [cifs] cifs_demultiplex_thread+0x1148/0x1740 [cifs] kthread+0x1cf/0x210
- Severity
- critical
- Software
- Kernel
- Fixed in
- 7.0.11
- Published
- 2026-07-19
Affected versions
From: 6.19
Until: 7.0.11
Fixed in: 7.0.11
How to fix this CVE
Update the Linux kernel to version 7.0.11 or later to patch a critical use-after-free vulnerability in the netfs subsystem's gap-filling logic. This flaw allows kernel memory corruption when handling network filesystem read operations, potentially leading to system crashes or privilege escalation. Ensure your system is rebooted after applying the kernel update to activate the patched version.
sudo dnf update kernel && sudo rebootDefensia detects this vulnerability
How to check if you are affected
- Check the current kernel version: uname -r (vulnerable if output shows 6.19.x through 7.0.10)
- Verify netfs module presence: grep -i netfs /proc/modules (confirm network filesystem support is active)
- Search kernel logs for UAF indicators: dmesg | grep -i 'KASAN\|use-after-free\|netfs' (look for memory sanitizer warnings)
- Confirm patch status: cat /proc/version | grep -q '7.0.11' && echo 'Patched' || echo 'Vulnerable'
FAQ
What is CVE-2026-64061?
This is a critical use-after-free vulnerability in the Linux kernel's netfs (network filesystem) subsystem that occurs during read gap-filling operations. The sink folio used to bridge data gaps is released prematurely, leaving a dangling pointer that can be accessed during subsequent network data reception, causing memory corruption.
Is CVE-2026-64061 being actively exploited?
No, CVE-2026-64061 is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog, and no public exploits are available. However, given its critical CVSS score of 9.8, it should be treated as an urgent patch priority.
What versions of Kernel are affected by CVE-2026-64061?
Linux kernel versions 6.19 through 7.0.10 are affected. Version 7.0.11 and later contain the fix.
How do I check if my server is vulnerable to CVE-2026-64061?
Run 'uname -r' and check if the output matches the 6.19.x through 7.0.10 range. Alternatively, compare your version number against the fixed version (7.0.11) to determine vulnerability status.
Does Defensia detect CVE-2026-64061?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2026-64061 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-64061. Free for 1 server.
Get started free