SB2026081604 - Improper Initialization in Linux kernel netfs
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper Initialization (CVE-ID: CVE-2026-72366)
CWE-ID: CWE-665 - Improper Initialization
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource initialization in netfs_create_write_req() when handling write operations during asynchronous cache object creation. A local user can trigger a write operation before the fscache cookie is fully enabled to cause a denial of service.
The issue occurs because caching may be skipped while asynchronous cache object creation has not progressed far enough for the cookie to be enabled.
Remediation
Install update from vendor's website.