CVE-2026-64217 is a vulnerability in Linux Kernel
Published on July 24, 2026
netfs: Fix overrun check in netfs_extract_user_iter()
In the Linux kernel, the following vulnerability has been resolved:
netfs: Fix overrun check in netfs_extract_user_iter()
Fix netfs_extract_user_iter() so that if iov_iter_extract_pages() overfills
pages[], then those pages don't get included in the iterator constructed at
the end of the function. If there was an overfill, memory corruption has
already happened.
Products Associated with CVE-2026-64217
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 85dd2c8ff368b1446be9febde84afe1d7aec4261 and below 00efe58bbdcc93272d579ca24bfc912563f4a204 is affected.
- Version 85dd2c8ff368b1446be9febde84afe1d7aec4261 and below 96cc3beb2390ba9f9c128c5733c0ccfe450dd4f9 is affected.
- Version 85dd2c8ff368b1446be9febde84afe1d7aec4261 and below afeb32d9bf9aaeea51d0f723a19f14afb73bd94d is affected.
- Version 85dd2c8ff368b1446be9febde84afe1d7aec4261 and below f48b9157f0f611fa436c360648603d5ded719b12 is affected.
- Version 85dd2c8ff368b1446be9febde84afe1d7aec4261 and below 0ef37eef83fad3542ee06db2940433ae1a92b39d is affected.
- Version 6.3 is affected.
- Before 6.3 is unaffected.
- Version 6.6.142, <= 6.6.* is unaffected.
- Version 6.12.92, <= 6.12.* is unaffected.
- Version 6.18.34, <= 6.18.* is unaffected.
- Version 7.0.11, <= 7.0.* is unaffected.
- Version 7.1, <= * is unaffected.