Improper Initialization in Linux kernel - CVE-2026-72366

 

Improper Initialization in Linux kernel - CVE-2026-72366

Published: August 16, 2026


Vulnerability identifier: #VU143066
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-72366
CWE-ID: CWE-665
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource initialization in netfs_create_write_req() when handling write operations during asynchronous cache object creation. A local user can trigger a write operation before the fscache cookie is fully enabled to cause a denial of service.

The issue occurs because caching may be skipped while asynchronous cache object creation has not progressed far enough for the cookie to be enabled.


Affected software

Linux kernel
Ubuntu
linux (Ubuntu package)
linux-gcp (Ubuntu package)

How to mitigate CVE-2026-72366

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Ubuntu package) - addressed in versions 7.0.0-34.34, 7.0.0-34.34.1, 7.0.0-34.34~24.04.1, 7.0.0-1012.12~24.04.1, 7.0.0-1013.13, 7.0.0-1013.13~24.04.1, 7.0.0-1014.14, 7.0.0-1020.20
linux-gcp (Ubuntu package) - addressed in versions 7.0.0-1013.13, 7.0.0-1013.13~24.04.1, 7.0.0-1014.14

External References

Related Security Bulletins