Linux Kernel Vulnerability in Netfs Affecting Data Integrity
CVE-2026-64159

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-64159?

A vulnerability in the Linux kernel's netfs component affects how file positions are managed. Specifically, it concerns the update of the zero point during operations with uncommitted data in the pagecache. If the local file size (i_size) exceeds the size on the remote server (remote_i_size), it can lead to discrepancies in data retrieval, resulting in potential short reads. This flaw was identified through specific test conditions, indicating that the update mechanism for zero points needs to align more closely with remote file status to ensure reliable data integrity and reduce unnecessary read operations.

Affected Version(s)

Linux cce6bfa6ca0e30af9927b0074c97fe6a92f28092 < 5cd5207de519ef0c085f4f559adf5eefcb4c5202

Linux cce6bfa6ca0e30af9927b0074c97fe6a92f28092 < 4543a4d737944134a1394afe797622546fbcc98a

Linux e2814004138a541110d4b2dc254a8f619c2c4ce0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.