Improper Initialization in Linux kernel - CVE-2026-72366
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource initialization in netfs_create_write_req() when handling write operations during asynchronous cache object creation. A local user can trigger a write operation before the fscache cookie is fully enabled to cause a denial of service.
The issue occurs because caching may be skipped while asynchronous cache object creation has not progressed far enough for the cookie to be enabled.
Affected software
Ubuntu
linux (Ubuntu package)
linux-gcp (Ubuntu package)
How to mitigate CVE-2026-72366
linux (Ubuntu package) - addressed in versions 7.0.0-34.34, 7.0.0-34.34.1, 7.0.0-34.34~24.04.1, 7.0.0-1012.12~24.04.1, 7.0.0-1013.13, 7.0.0-1013.13~24.04.1, 7.0.0-1014.14, 7.0.0-1020.20
linux-gcp (Ubuntu package) - addressed in versions 7.0.0-1013.13, 7.0.0-1013.13~24.04.1, 7.0.0-1014.14