PT-2026-61476 · Linux+1 · Linux Kernel+1

CVE-2026-64159

·

Published

2026-07-19

·

Updated

2026-09-07

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the netfs component where the zero point—the file position from which the system assumes the server will return zeros to avoid unnecessary reads—is updated incorrectly by the netfs release folio() function. This occurs when uncommitted data exists in the pagecache beyond the folio being released, but the on-server end-of-file (EOF) is within that folio, leading to a situation where i size is greater than remote i size. The update incorrectly uses i size, which reflects local pagecache updates, instead of remote i size, which tracks the actual server file size.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-64159
USN-8593-1
USN-8603-1
USN-8618-1
USN-8663-1
USN-8664-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu