Memory Corruption Vulnerability in Linux Kernel Affecting Netfile Systems
CVE-2026-64217
What is CVE-2026-64217?
A vulnerability has been identified in the Linux kernel related to netfile systems, specifically in the function netfs_extract_user_iter(). An issue arises when iov_iter_extract_pages() incorrectly calculates the size of pages[], resulting in a memory overrun. This could lead to memory corruption, causing potential security risks. The vulnerability was addressed by ensuring that any overflow does not include the overfilled pages in the iterator, which is crucial for maintaining system integrity. Users of affected kernel versions should apply the necessary patches to mitigate risks.
Affected Version(s)
Linux 85dd2c8ff368b1446be9febde84afe1d7aec4261 < 00efe58bbdcc93272d579ca24bfc912563f4a204
Linux 85dd2c8ff368b1446be9febde84afe1d7aec4261 < 96cc3beb2390ba9f9c128c5733c0ccfe450dd4f9
Linux 85dd2c8ff368b1446be9febde84afe1d7aec4261