In the Linux kernel, the following vulnerability has been resolved:
netfs: Fix copy-to-cache so that it performs collection with ceph+fscache
The netfs copy-to-cache that is used by Ceph with local caching sets up a new request to write data just read to the cache. The request is started and then left to look after itself whilst the app continues. The request gets notified by the backing fs upon completion of the async DIO write, but then tries to wake up the app because NETFS_RREQ_OFFLOAD_COLLECTION isn't set - but the app isn't waiting there, and so the request just hangs.
Fix this by setting NETFS_RREQ_OFFLOAD_COLLECTION which causes the notification from the backing filesystem to put the collection onto a work queue instead.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Ubuntu | — | Upgrade linux-image-oracle-64kUpgrade linux-image-azure-6.14Upgrade linux-image-generic-64kUpgrade linux-image-genericUpgrade linux-image-aws-64kUpgrade linux-image-6.14.0-1017-oracle-64kUpgrade linux-image-virtual-6.14Upgrade linux-image-raspi-6.14Upgrade linux-image-6.14.0-1017-azureUpgrade linux-image-realtime-hwe-24.04Upgrade linux-image-6.14.0-1018-raspiUpgrade linux-image-gcp-6.14Upgrade linux-image-gcpUpgrade linux-image-6.14.0-1017-awsUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-generic-6.14Upgrade linux-image-oem-24.04Upgrade linux-image-oem-24.04aUpgrade linux-image-raspiUpgrade linux-image-azureUpgrade linux-image-gcp-64kUpgrade linux-image-6.14.0-1020-gcp-64kUpgrade linux-image-oracle-64k-6.14Upgrade linux-image-awsUpgrade linux-image-oem-6.14Upgrade linux-image-generic-hwe-24.04Upgrade linux-image-6.14.0-1016-oemUpgrade linux-image-virtualUpgrade linux-image-realtimeUpgrade linux-image-6.14.0-1016-realtimeUpgrade linux-image-generic-64k-6.14Upgrade linux-image-aws-64k-6.14Upgrade linux-image-6.14.0-1017-aws-64kUpgrade linux-image-oracleUpgrade linux-image-6.14.0-1020-gcpUpgrade linux-image-6.14.0-1017-oracleUpgrade linux-image-aws-6.14Upgrade linux-image-gcp-64k-6.14Upgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-realtime-6.14Upgrade linux-image-oracle-6.14Upgrade linux-image-6.14.0-36-generic-64kUpgrade linux-image-6.14.0-36-generic | Nov 25, 2025 | Nov 21, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub