{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-64067","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T07:54:57.030Z","datePublished":"2026-07-19T15:39:44.660Z","dateUpdated":"2026-07-20T13:42:58.657Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-07-20T13:42:58.657Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix missing barriers when accessing stream->subrequests locklessly\n\nThe list of subrequests attached to stream->subrequests is accessed without\nlocks by netfs_collect_read_results() and netfs_collect_write_results(),\nand then they access subreq->flags without taking a barrier after getting\nthe subreq pointer from the list.  Relatedly, the functions that build the\nlist don't use any sort of write barrier when constructing the list to make\nsure that the NETFS_SREQ_IN_PROGRESS flag is perceived to be set first if\nno lock is taken.\n\nFix this by:\n\n (1) Add a new list_add_tail_release() function that uses a release barrier\n     to set the pointer to the new member of the list.\n\n (2) Add a new list_first_entry_or_null_acquire() function that uses an\n     acquire barrier to read the pointer to the first member in a list (or\n     return NULL).\n\n (3) Use list_add_tail_release() when adding a subreq to ->subrequests.\n\n (4) Use list_first_entry_or_null_acquire() when initially accessing the\n     front of the list (when an item is removed, the pointer to the new\n     front iterm is obtained under the same lock)."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"}}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/netfs/buffered_read.c","fs/netfs/misc.c","fs/netfs/read_collect.c","fs/netfs/write_collect.c","fs/netfs/write_issue.c","include/linux/list.h"],"versions":[{"version":"288ace2f57c9d06dd2e42bd80d03747d879a4068","lessThan":"293a4532c36f38458e38b8879b174ab797718b9d","status":"affected","versionType":"git"},{"version":"288ace2f57c9d06dd2e42bd80d03747d879a4068","lessThan":"b5782e2d462c028096f922abca46318cec890670","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/netfs/buffered_read.c","fs/netfs/misc.c","fs/netfs/read_collect.c","fs/netfs/write_collect.c","fs/netfs/write_issue.c","include/linux/list.h"],"versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","status":"unaffected","versionType":"semver"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"7.0.11"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/293a4532c36f38458e38b8879b174ab797718b9d"},{"url":"https://git.kernel.org/stable/c/b5782e2d462c028096f922abca46318cec890670"}],"title":"netfs: Fix missing barriers when accessing stream->subrequests locklessly","x_generator":{"engine":"bippy-1.2.0"}}}}