In the Linux kernel, the following vulnerability has been resolved:
netfs: Fix missing barriers when accessing stream->subrequests locklessly
The list of subrequests attached to stream->subrequests is accessed without locks by netfs_collect_read_results() and netfs_collect_write_results(), and then they access subreq->flags without taking a barrier after getting the subreq pointer from the list. Relatedly, the functions that build the list don't use any sort of write barrier when constructing the list to make sure that the NETFS_SREQ_IN_PROGRESS flag is perceived to be set first if no lock is taken.
Fix this by:
(1) Add a new list_add_tail_release() function that uses a release barrier to set the pointer to the new member of the list.
(2) Add a new list_first_entry_or_null_acquire() function that uses an acquire barrier to read the pointer to the first member in a list (or return NULL).
(3) Use list_add_tail_release() when adding a subreq to ->subrequests.
(4) Use list_first_entry_or_null_acquire() when initially accessing the front of the list (when an item is removed, the pointer to the new front iterm is obtained under the same lock).
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Ubuntu | — | Upgrade linux-image-7.0.0-1011-gcp-64kUpgrade linux-image-raspiUpgrade linux-image-7.0.0-1014-azureUpgrade linux-image-7.0.0-1016-nvidiaUpgrade linux-image-nvidia-hwe-26.04Upgrade linux-image-ibm-7.0Upgrade linux-image-azureUpgrade linux-image-7.0.0-1008-oracleUpgrade linux-image-raspi-realtimeUpgrade linux-image-gcpUpgrade linux-image-nvidia-64k-hwe-26.04Upgrade linux-image-7.0.0-1015-raspiUpgrade linux-image-nvidia-7.0Upgrade linux-image-aws-64kUpgrade linux-image-7.0.0-1011-oracleUpgrade linux-image-7.0.0-1016-nvidia-64kUpgrade linux-image-gcp-64k-7.0Upgrade linux-image-nvidia-64kUpgrade linux-image-nvidia-bos-64k-7.0Upgrade linux-image-nvidia-bosUpgrade linux-image-7.0.0-2016-nvidia-bosUpgrade linux-image-azure-7.0Upgrade linux-image-azure-fdeUpgrade linux-image-gcp-64kUpgrade linux-image-oracle-64kUpgrade linux-image-nvidia-bos-64kUpgrade linux-image-nvidia-bos-7.0Upgrade linux-image-7.0.0-1010-ibmUpgrade linux-image-7.0.0-1008-oracle-64kUpgrade linux-image-nvidia-64k-7.0Upgrade linux-image-7.0.0-2016-nvidia-bos-64kUpgrade linux-image-7.0.0-1009-awsUpgrade linux-image-raspi-realtime-7.0Upgrade linux-image-oracleUpgrade linux-image-raspi-7.0Upgrade linux-image-nvidiaUpgrade linux-image-7.0.0-1009-azure-fdeUpgrade linux-image-oracle-64k-7.0Upgrade linux-image-aws-7.0Upgrade linux-image-gcp-7.0Upgrade linux-image-7.0.0-1010-azureUpgrade linux-image-oracle-7.0Upgrade linux-image-aws-64k-7.0Upgrade linux-image-awsUpgrade linux-image-7.0.0-1009-aws-64kUpgrade linux-image-azure-fde-7.0Upgrade linux-image-7.0.0-1011-oracle-64kUpgrade linux-image-ibmUpgrade linux-image-7.0.0-1015-raspi-realtimeUpgrade linux-image-7.0.0-1011-gcp | Jul 21, 2026 | Jul 20, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 27, 2026 | Jul 19, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub