Race condition in Linux kernel - CVE-2026-64067
Published: July 20, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to missing memory barriers in netfs subrequest list handling when processing netfs read and write subrequests locklessly. A local user can trigger concurrent read or write operations to cause a denial of service.
The issue affects access to stream->subrequests and subreq->flags in netfs_collect_read_results(), netfs_collect_write_results(), and related queueing logic.