Kestrel
대시보드로 돌아가기
CVE-2026-64063UNKNOWNMITRENVD대응게시일: 2026. 07. 19.수정일: 2026. 07. 19.CNA: 416baaa9-dc9f-4396-8d5f-8c081fb06d67Received

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix streaming write being overwritten In order to avoid reading

위협 신호 · CVSS · EPSS · KEV

정기 패치· 높은 악용 신호 없음
CVSS
unknown

이론적 심각도 점수

EPSS
0.2%상위 93.6%

30일 내 악용 확률 예측

KEV
미등재

실측 악용 기록 없음

권장 대응 기한60일 이내CISA SSVC 기준

계획된 패치 주기 내 조치(60일 이내)

외부 노출· KEV 미등재 · 자동화 어려움 · 부분 영향 · 외부 노출

CVSS 벡터 · 메트릭

CVSS 벡터 정보 없음

상세 설명

In the Linux kernel, the following vulnerability has been resolved:

netfs: Fix streaming write being overwritten

In order to avoid reading whilst writing, netfslib will allow "streaming
writes" in which dirty data is stored directly into folios without reading
them first. Such folios are marked dirty but may not be marked uptodate.
If a folio is entirely written by a streaming write, uptodate will be set,
otherwise it will have a netfs_folio struct attached to ->private recording
the dirty region.

In the event that a partially written streaming write page is to be
overwritten entirely by a single write(), netfs_perform_write() will try to
copy over it, but doesn't discard the netfs_folio if it succeeds; further,
it doesn't correctly handle a partial copy that overwrites some of the
dirty data.

Fix this by the following:

(1) If the folio is successfully overwritten, free the netfs_folio struct
before marking the page uptodate.

(2) If the copy to the folio partially fails, but short of the dirty data,
just ignore the copy.

(3) If the copy partially fails and overwrites some of the dirty data,
accept the copy, update the netfs_folio struct to record the new data.
If the folio is now filled, free the netfs_folio and set uptodate,
otherwise return a partial write.

Found with:

text
1fsx -q -N 1000000 -p 10000 -o 128000 -l 600000 \
2 /xfstest.test/junk --replay-ops=junk.fsxops

using the following as junk.fsxops:

text
1truncate 0x0 0 0x927c0
2write 0x63fb8 0x53c8 0
3copy_range 0xb704 0x19b9 0x24429 0x79380
4write 0x2402b 0x144a2 0x90660 *
5write 0x204d5 0x140a0 0x927c0 *
6copy_range 0x1f72c 0x137d0 0x7a906 0x927c0 *
7read 0x00000 0x20000 0x9157c
8read 0x20000 0x20000 0x9157c
9read 0x40000 0x20000 0x9157c
10read 0x60000 0x20000 0x9157c
11read 0x7e1a0 0xcfb9 0x9157c

on cifs with the default cache option.

It shows folio 0x24 misbehaving if the FMODE_READ check is commented out in
netfs_perform_write():

text
1 if (//(file->f_mode & FMODE_READ) ||
2 netfs_is_cache_enabled(ctx)) {

and no fscache. This was initially found with the generic/522 xfstest.

AI 심층 분석

공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.