CVE-2026-64061: netfs: Fix early put of sink folio in netfs_read_gaps()
In the Linux kernel, the following vulnerability has been resolved:
netfs: Fix early put of sink folio in netfs_read_gaps()
Fix netfs_read_gaps() to release the sink page it uses after waiting for
the request to complete. The way the sink page is used is that an
ITER_BVEC-class iterator is created that has the gaps from the target folio
at either end, but has the sink page tiled over the middle so that a single
read op can fill in both gaps.
The bug was found by KASAN detecting a UAF on the generic/075 xfstest in
the cifsd kernel thread that handles reception of data from the TCP socket:
BUG: KASAN: use-after-free in _copy_to_iter+0x48a/0xa20
Write of size 885 at addr ffff888107f92000 by task cifsd/1285
CPU: 2 UID: 0 PID: 1285 Comm: cifsd Not tainted 7.0.0 #6 PREEMPT(lazy)
Call Trace:
dump_stack_lvl+0x5d/0x80
print_report+0x17f/0x4f1
kasan_report+0x100/0x1e0
kasan_check_range+0x10f/0x1e0
__asan_memcpy+0x3c/0x60
_copy_to_iter+0x48a/0xa20
__skb_datagram_iter+0x2c9/0x430
skb_copy_datagram_iter+0x6e/0x160
tcp_recvmsg_locked+0xce0/0x1130
tcp_recvmsg+0xeb/0x300
inet_recvmsg+0xcf/0x3a0
sock_recvmsg+0xea/0x100
cifs_readv_from_socket+0x3a6/0x4d0 [cifs]
cifs_read_iter_from_socket+0xdd/0x130 [cifs]
cifs_readv_receive+0xaad/0xb10 [cifs]
cifs_demultiplex_thread+0x1148/0x1740 [cifs]
kthread+0x1cf/0x210
Security readout for executives and security teams
Plain-English summary
CVE-2026-64061 is a Linux kernel memory-safety flaw in netfs read handling. A page used during reads can be released too early, creating a use-after-free. The source assigns critical severity and CVSS 9.8, but does not show public exploitation.
Executive priority
Treat as urgent for Linux fleets, especially file-serving or network-filesystem workloads. Patch through trusted kernel channels, but avoid claiming compromise unless telemetry or vendor intelligence supports it.
Technical view
The bug is in netfs_read_gaps(), which releases a sink folio before the read request completes. KASAN detected a use-after-free during xfstest generic/075 in a CIFS kernel thread receiving TCP socket data, with writes occurring through _copy_to_iter().
Likely exposure
Exposure is most relevant to Linux systems running affected kernel builds with netfs/CIFS-style read paths. The bundle lists Linux as affected, but exact distribution package exposure and fixed version mapping require kernel or distro advisory confirmation.
Exploitation context
The CVSS vector indicates network attack potential without privileges or user interaction. However, KEV is false and the supplied sources do not cite active exploitation, public exploit code, or real-world attacks.
Researcher notes
Evidence is limited to the CVE text and kernel stable references. The report identifies a KASAN-confirmed UAF and associated CIFS receive path, but does not provide exploitability details beyond CVSS scoring.
Mitigation direction
Review the linked Linux stable commits and vendor kernel advisories.
Prioritize kernel updates once your distribution publishes fixed packages.
Track systems using CIFS, SMB, or netfs-backed file access.
Apply compensating access controls around exposed network file services where feasible.
Validation and detection
Inventory Linux kernel versions across servers and appliances.
Map installed distro kernels to vendor advisories for CVE-2026-64061.
Identify hosts using CIFS, SMB, or netfs read paths.
Check vulnerability scanners for authenticated kernel package detection.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2026-64061 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
0ADP providers
5Source links
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.