SB2026081604 - Improper Initialization in Linux kernel netfs



SB2026081604 - Improper Initialization in Linux kernel netfs

Published: August 16, 2026

Security Bulletin ID SB2026081604
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper Initialization (CVE-ID: CVE-2026-72366)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource initialization in netfs_create_write_req() when handling write operations during asynchronous cache object creation. A local user can trigger a write operation before the fscache cookie is fully enabled to cause a denial of service.

The issue occurs because caching may be skipped while asynchronous cache object creation has not progressed far enough for the cookie to be enabled.


Remediation

Install update from vendor's website.