Description
There are packages installed that are affected by a vulnerability referenced in the following CVE:
- In the Linux kernel, the following vulnerability has been resolved: netfs: Fix zeropoint update where
i_size > remote_i_size Fix the update of the zero point[*] by netfs_release_folio() when there is
uncommitted data in the pagecache beyond the folio being released but the on-server EOF is in this folio
(ie. i_size > remote_i_size). The update needs to limit zero_point to remote_i_size, not i_size as i_size
is a local phenomenon reflecting updates made locally to the pagecache, not stuff written to the server.
remote_i_size tracks the server's i_size. [*] The zero point is the file position from which we can assume
that the server will just return zeros, so we can avoid generating reads. Note that
netfs_invalidate_folio() probably doesn't need fixing as zero_point should be updated by setattr after
truncation or fallocate. Found with: fsx -q -N 1000000 -p 10000 -o 128000 -l 600000 \ /xfstest.test/junk
--replay-ops=junk.fsxops using the following as junk.fsxops: truncate 0x0 0x1bbae 0x82864 write 0x3ef2e
0xf9c8 0x1bbae write 0x67e05 0xcb5a 0x4e8f6 mapread 0x57781 0x85b6 0x7495f copy_range 0x5d3d 0x10329
0x54fac 0x7495f write 0x64710 0x1c2b 0x7495f mapread 0x64000 0x1000 0x7495f on cifs with the default cache
option. It shows read-gaps on folio 0x64 failing with a short read (ie. it hits EOF) if the FMODE_READ
check is commented out in netfs_perform_write(): if (//(file->f_mode & FMODE_READ) ||
netfs_is_cache_enabled(ctx)) { and no fscache. This was initially found with the generic/522 xfstest.
(CVE-2026-64159)
Solution
Update the linux-qemu-melange library and its related packages to version 6.18.49-r2 or later.
Plugin Details
Risk Information
Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Vulnerability Information
Exploit Ease: No known exploits are available
Vulnerability Publication Date: 7/19/2026