SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-64217

HIGH · CVSS 7.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

A vulnerability in the Linux kernel's netfs component allows for potential memory corruption due to improper handling of page overflows in the netfs_extract_user_iter() function. This could lead to unauthorized access or manipulation of memory, impacting system stability and security. Organizations using affected Linux distributions should prioritize patching this vulnerability to mitigate risks associated with compromised system integrity.

CVE
CVE-2026-64217
Severity
HIGH
CVSS
7.8
EPSS
0.13%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix overrun check in netfs_extract_user_iter() Fix netfs_extract_user_iter() so that if iov_iter_extract_pages() overfills pages[], then those pages don't get included in the iterator constructed at the end of the function. If there was an overfill, memory corruption has already happened.

Related CVEs

Other vulnerabilities affecting the same vendor(s)