CVE-2026-64066
A critical flaw in the Linux kernel’s netfs subsystem could let an attacker trigger a denial‑of‑service by exploiting how subrequests are handled. The bug occurs when netfs_read_to_pagecache() does not pause after a subrequest fails, potentially exhausting system resources. The issue has been fixed in recent kernel releases.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel users running a version before the netfs_read_to_pagecache() fix, especially those using the netfs filesystem.
Real-world impact
An attacker could cause the system to become unresponsive by repeatedly triggering subrequest failures, leading to resource exhaustion and denial of service.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability can be exploited remotely without authentication or user interaction, and it can compromise confidentiality, integrity, and availability.
What to do about it
- 01Install a Linux kernel update that includes the netfs_read_to_pagecache() fix.
- 02Reboot the system to load the new kernel.
NVD description indicates the issue has been resolved in the Linux kernel.
Timeline
- Jul 19, 2026 · 14d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 13d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 30, 2026 · 3d agoAdvisory updatedThe NVD record was last revised.