Linux Kernel Vulnerability Affecting Netfs Components
CVE-2026-98120

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-98120?

A vulnerability has been identified in the Linux kernel's netfs component related to subrequest reference leaks. This issue arises specifically in the netfs_unbuffered_write() function when a subrequest's IO iterator results in zero length during its preparation phase. The improper management of subrequest references can lead to potentially unintended behavior in the system, undermining the reliability and security of the kernel's operations. The vulnerability has been addressed in a recent update, and it is crucial for users to apply the latest patches to maintain system integrity.

Affected Version(s)

Linux 72d08d2839649d1c5efbe375751f4473fa4486af

Linux a0b4c7a49137ed21279f354eb59f49ddae8dffc2 < 0a573f4283a965a5e8716f621aec404cb4575328

Linux a0b4c7a49137ed21279f354eb59f49ddae8dffc2 < 3c30087e27598d9d359763e8be9bd3017fe08348

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.