CVE-2026-64216·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages() netfs_unlock_abandoned_read_pages(rreq) accesses the index of the folios it is wanting to unlock and compares that to rreq->no_unlock_folio so that it doesn't unlock a folio being read for netfs_perform_write() or netfs_write_begin(). However, given that netfs_unlock_abandoned_read_pages() is called _after_ NETFS_RREQ_IN_PROGRESS is cleared, the one folio that it's not allowed to dereference is the one specified by ->no_unlock_folio as ownership immediately reverts to the caller. Fix this by storing the folio pointer instead and using that rather than the index. Also fix netfs_unlock_read_folio() where the same applies.
- Severity
- critical
- Software
- Kernel
- Fixed in
- 7.0.11
- Published
- 2026-07-24
Affected versions
From: 6.19
Until: 7.0.11
Fixed in: 7.0.11
How to fix this CVE
Update your Linux kernel to version 7.0.11 or later to fix a use-after-free vulnerability in the netfs subsystem that could cause memory corruption or denial of service. This critical issue affects the kernel's network filesystem handling during concurrent read and write operations. Apply the patch immediately on all affected systems running kernel versions 6.19 through 7.0.10.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Check the installed kernel version: uname -r — verify it is 7.0.11 or later
- List all netfs-related modules: lsmod | grep netfs — check if netfs is loaded in your kernel
- Search kernel logs for UAF signatures: dmesg | grep -i 'use.after.free\|netfs\|unlock' — look for memory safety warnings
- Verify the patch application: grep -r 'netfs_unlock_abandoned_read_pages\|no_unlock_folio' /usr/src/linux-headers-*/net/netfs/ — confirm folio pointer storage is used instead of index
FAQ
What is CVE-2026-64216?
This is a use-after-free vulnerability in the Linux kernel's netfs (network filesystem) subsystem where the kernel incorrectly dereferences a folio pointer after releasing ownership during concurrent read and write operations, potentially leading to memory corruption or system crash.
Is CVE-2026-64216 being actively exploited?
No, there is no evidence of active exploitation or public exploits available for this vulnerability at this time.
What versions of Kernel are affected by CVE-2026-64216?
Linux kernel versions 6.19 through 7.0.10 are vulnerable. Kernel 7.0.11 and later versions contain the fix.
How do I check if my server is vulnerable to CVE-2026-64216?
Run 'uname -r' to check your kernel version. If it reports a version between 6.19 and 7.0.10, your system is vulnerable and requires immediate patching.
Does Defensia detect CVE-2026-64216?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2026-64216 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-64216. Free for 1 server.
Get started free