CVE-2026-64069
A flaw in the Linux kernel’s network filesystem handling could allow an attacker to read, modify, or delete data on the system. The issue was fixed in a kernel update that corrects how read subrequests are cancelled and queued.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
All users running Linux kernel versions that contain the vulnerable netfs read handling code – typically older kernel releases before the patch was applied.
Real-world impact
An attacker who can reach the affected system over the network could read sensitive data, alter files, or disrupt services by exploiting the faulty read request handling.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability can be exploited remotely (network access), requires no user interaction, and gives an attacker full control over confidentiality, integrity, and availability of the system.
What to do about it
- 01Identify the current Linux kernel version you are running.
- 02Update the kernel to a version that includes the CVE-2026-64069 fix – e.g., install the latest stable kernel release from your distribution’s repository.
NVD-referenced vendor advisory
Timeline
- Jul 19, 2026 · 14d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 13d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 30, 2026 · 3d agoAdvisory updatedThe NVD record was last revised.