Skip to content
CVSS 9.8 · CRITICAL

CVE-2026-64066Critical vulnerability in Linux kernel netfs subsystem

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix netfs_read_to_pagecache() to pause on subreq failure Fix netfs_read_to_pagecache() so that it pauses the generation of new subrequests if an already-issued subrequest fails.

View on NVD

Analysis

A critical vulnerability has been identified in the Linux kernel netfs subsystem. Given the 9.8 CVSS score and the nature of network filesystems, this could potentially allow remote exploitation or lead to severe system instability for servers using network-backed storage.

Relevant roles

LinuxDockerKubernetesCloudBackendCyberSecurity

Severity

Score: 9.8(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-125

EPSS

Probability of exploitation (next 30 days): 0.0044 (0.4%)
Percentile: 37.0%
EPSS: 2026-09-03

Affects

linux:linux_kernel

Technical description

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix netfs_read_to_pagecache() to pause on subreq failure Fix netfs_read_to_pagecache() so that it pauses the generation of new subrequests if an already-issued subrequest fails.

Published: 7/19/2026, 4:17:47 PM
Last modified: 9/3/2026, 3:35:09 PM

References

HomeEventsBlogResourcesCoursesTeam