CVE-2026-64067

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/07/2026
Last modified:
30/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> netfs: Fix missing barriers when accessing stream-&gt;subrequests locklessly<br /> <br /> The list of subrequests attached to stream-&gt;subrequests is accessed without<br /> locks by netfs_collect_read_results() and netfs_collect_write_results(),<br /> and then they access subreq-&gt;flags without taking a barrier after getting<br /> the subreq pointer from the list. Relatedly, the functions that build the<br /> list don&amp;#39;t use any sort of write barrier when constructing the list to make<br /> sure that the NETFS_SREQ_IN_PROGRESS flag is perceived to be set first if<br /> no lock is taken.<br /> <br /> Fix this by:<br /> <br /> (1) Add a new list_add_tail_release() function that uses a release barrier<br /> to set the pointer to the new member of the list.<br /> <br /> (2) Add a new list_first_entry_or_null_acquire() function that uses an<br /> acquire barrier to read the pointer to the first member in a list (or<br /> return NULL).<br /> <br /> (3) Use list_add_tail_release() when adding a subreq to -&gt;subrequests.<br /> <br /> (4) Use list_first_entry_or_null_acquire() when initially accessing the<br /> front of the list (when an item is removed, the pointer to the new<br /> front iterm is obtained under the same lock).