Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-72132— NFS: Charge unstable writes by request size, not folio size

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel 6.3版本存在安全漏洞,该漏洞源于NFS不稳定写入按folio大小而非请求大小进行计费,导致写回计数膨胀,可能迫使主机上所有缓冲写入器进入硬节流路径。

AI Predicted 7.5 Difficulty: Moderate EPSS 0.20% · P10

Affected Version Matrix 12

VendorProduct Version RangeStatus
Linux Linux 0c493b5cf16e28d761b6e77c7c32aa0e7af70813< a442c258320b689f13d2205eaeeddf8b0e630288 affected
0c493b5cf16e28d761b6e77c7c32aa0e7af70813< 1f646e23372f3444dc5f0bcb5404a49d26756add affected
0c493b5cf16e28d761b6e77c7c32aa0e7af70813< 0ffc032294a29601b1019dba91aa1a930d90df17 affected
0c493b5cf16e28d761b6e77c7c32aa0e7af70813< a192b6c149c6ea10cc88869accb78165eb454456 affected
0c493b5cf16e28d761b6e77c7c32aa0e7af70813< 27934d02cbeb8a957dd11c985a579e58d30c5270 affected
6.3 affected
< 6.3 unaffected
6.6.148≤ 6.6.* unaffected
… +4 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-72132

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
NFS: Charge unstable writes by request size, not folio size
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: NFS: Charge unstable writes by request size, not folio size nfs_folio_mark_unstable() and nfs_folio_clear_commit() charge and uncharge NR_WRITEBACK/WB_WRITEBACK by folio_nr_pages(folio) once per *request* added to or removed from a commit list. This is correct only when a folio has a single associated request. When pg_test splits a folio into N sub-folio requests (e.g. pNFS flexfiles striping with a stripe unit smaller than the folio size, or plain wsize-limited splitting), each of the N requests independently charges the whole folio's page count, inflating the accounting by a factor of N per folio. With large folios and small stripe units this reaches multiple orders of magnitude: a 2 MiB folio split into 512 4 KiB requests can charge up to 512x its real size, pushing global dirty+writeback accounting past the system's dirty threshold and forcing every buffered writer on the host into the hard-throttle path, including unrelated in-kernel NFS server threads sharing the box. Charge each request only for the pages it actually covers.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel 6.3版本存在安全漏洞,该漏洞源于NFS不稳定写入按folio大小而非请求大小进行计费,导致写回计数膨胀,可能迫使主机上所有缓冲写入器进入硬节流路径。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 0c493b5cf16e28d761b6e77c7c32aa0e7af70813 ~ a442c258320b689f13d2205eaeeddf8b0e630288 -
Linux Linux 6.3 -

II. Public POCs for CVE-2026-72132

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-72132

登录查看更多情报信息。

Patches & Fixes for CVE-2026-72132 (4)

Other References for CVE-2026-72132 (1)

Same Patch Batch · Linux · 2026-08-15 · 845 CVEs total

CVE-2026-74475 10.0 CRITICAL vxlan: use neigh_ha_snapshot() in route_shortcircuit()
CVE-2026-74280 10.0 CRITICAL crypto: marvell/octeontx - fix DMA cleanup using wrong loop index
CVE-2026-74279 10.0 CRITICAL crypto: cavium/cpt - fix DMA cleanup using wrong loop index
CVE-2026-72408 10.0 CRITICAL geneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint
CVE-2026-74309 10.0 CRITICAL vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler
CVE-2026-72421 10.0 CRITICAL ipv4: fib: Don't ignore error route in local/main tables.
CVE-2026-72407 10.0 CRITICAL geneve: validate inner network offset in geneve_gro_complete()
CVE-2026-72493 9.9 CRITICAL net: serialize netif_running() check in enqueue_to_backlog()
CVE-2026-72065 9.8 CRITICAL net: mana: Validate the packet length reported by the NIC
CVE-2026-74361 9.8 CRITICAL nvme: fix FDP fdpcidx bounds check
CVE-2026-72064 9.8 CRITICAL net: mana: Sync page pool RX frags for CPU
CVE-2026-74480 9.8 CRITICAL net: bridge: stop fast-leave after deleting a port group
CVE-2026-72191 9.8 CRITICAL ntfs3: validate split-point offset in indx_insert_into_buffer
CVE-2026-72192 9.8 CRITICAL ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head
CVE-2026-74478 9.8 CRITICAL um: vector: fix use-after-free in vector_mmsg_rx()
CVE-2026-72194 9.8 CRITICAL fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow
CVE-2026-74269 9.8 CRITICAL bnxt: fix head underflow on XDP head-grow
CVE-2026-72209 9.8 CRITICAL ntfs: validate attribute values on lookup
CVE-2026-72211 9.8 CRITICAL ntfs: grow index root value before reparent header update
CVE-2026-72041 9.8 CRITICAL espintcp: use sk_msg_free_partial to fix partial send

Showing top 20 of 845 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-72132

No comments yet


Leave a comment