In the Linux kernel, the following vulnerability has been resolved:
netfs: Fix the (non-)cancellation of copy when cache is temporarily disabled
When the caching for a cookie is temporarily disabled (e.g. due to a DIO write on that file), future copying to the cache for that file is disabled until all fds open on that file are closed. However, if netfslib is using the deprecated PG_private_2 method (such as is currently used by ceph), and decides it wants to copy to the cache, netfs_advance_write() will just bail at the first check seeing that the cache stream is unavailable, and indicate that it dealt with all the content.
This means that we have no subrequests to provide notifications to drive the state machine or even to pin the request and the request just gets discarded, leaving the folios with PG_private_2 set.
Fix this by jumping directly to cancel the request if the cache is not available. That way, we don't remove mark3 from the folio_queue list and netfs_pgpriv2_cancel() will clean up the folios.
This was found by running the generic/013 xfstest against ceph with an active cache and the "-o fsc" option passed to ceph. That would usually hang
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 27, 2026 | Jul 27, 2026 |
| Oracle_linux | — | Upgrade kernel | Dec 3, 2025 | Jan 21, 2025 |
| Redhat_linux | — | Upgrade kernel-rtUpgrade kernel | Jan 27, 2026 | Jan 21, 2025 |
| Rocky_linux | — | Upgrade kernel-debug-develUpgrade kernel-debug-coreUpgrade kernel-rt-debug-modules-extraUpgrade libperfUpgrade kernel-debuginfoUpgrade kernel-zfcpdumpUpgrade kernel-zfcpdump-modules-extraUpgrade kernel-rt-debug-modulesUpgrade kernel-debug-devel-matchedUpgrade perfUpgrade rtlaUpgrade kernel-modulesUpgrade kernel-tools-debuginfoUpgrade kernel-modules-coreUpgrade kernel-rt-coreUpgrade kernel-uki-virtUpgrade perf-debuginfoUpgrade kernel-debug-debuginfoUpgrade kernel-rt-debug-modules-coreUpgrade kernel-debugUpgrade kernel-modules-extraUpgrade kernel-debug-uki-virtUpgrade kernel-devel-matchedUpgrade kernel-rt-debug-develUpgrade kernel-coreUpgrade kernel-zfcpdump-develUpgrade python3-perfUpgrade kernel-rtUpgrade kernel-zfcpdump-modulesUpgrade kernel-rt-debug-debuginfoUpgrade kernel-modules-extra-matchedUpgrade kernel-debug-modules-coreUpgrade kernel-rt-develUpgrade kernel-rt-debuginfoUpgrade python3-perf-debuginfoUpgrade libperf-debuginfoUpgrade kernel-debuginfo-common-x86_64Upgrade kernel-debug-modulesUpgrade kernel-rt-debug-coreUpgrade rvUpgrade kernel-uki-virt-addonsUpgrade kernel-rt-modules-coreUpgrade kernelUpgrade kernel-tools-libsUpgrade kernel-rt-debugUpgrade kernel-debuginfo-common-s390xUpgrade kernel-develUpgrade kernel-zfcpdump-modules-coreUpgrade kernel-rt-modulesUpgrade kernel-debug-modules-extraUpgrade kernel-zfcpdump-debuginfoUpgrade kernel-zfcpdump-coreUpgrade kernel-tools-libs-develUpgrade kernel-rt-modules-extraUpgrade kernel-zfcpdump-devel-matchedUpgrade kernel-tools | Feb 5, 2026 | Nov 27, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub