Linux Kernel Directory Write Handling Vulnerability in AFS Component
CVE-2026-64156
What is CVE-2026-64156?
In the Linux kernel's AFS component, a vulnerability was identified that relates to improper handling of write operations within directories. Specifically, the netfs_write_single() and afs_single_writepages() functions failed to manage lock contention correctly, potentially leading to skipped writes. The update rectifies this issue by ensuring that if a write is skipped, the system appropriately returns a success indicator and re-marks the inode status, mitigating risks associated with write operations in directory contexts.
Affected Version(s)
Linux 6dd80936618c4ff852d4db73aca400351d9bd9f0 < 77bb293049d61e04c12b24ebbffafaf5ab36af90
Linux 6dd80936618c4ff852d4db73aca400351d9bd9f0
Linux 6dd80936618c4ff852d4db73aca400351d9bd9f0 < 9871938f99cc6cb266a77265491660e2375271f5