CVE-2026-64217
Published Jul 24, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix overrun check in netfs_extract_user_iter() Fix netfs_extract_user_iter() so that if iov_iter_extract_pages() overfills pages[], then those pages don't get included in the iterator constructed at the end of the function. If there was an overfill, memory corruption has already happened.
Is your site exposed to CVE-2026-64217?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/00efe58bbdcc93272d579ca24bfc912563f4a204
https://git.kernel.org/stable/c/0ef37eef83fad3542ee06db2940433ae1a92b39d
https://git.kernel.org/stable/c/96cc3beb2390ba9f9c128c5733c0ccfe450dd4f9
https://git.kernel.org/stable/c/afeb32d9bf9aaeea51d0f723a19f14afb73bd94d
https://git.kernel.org/stable/c/f48b9157f0f611fa436c360648603d5ded719b12
Frequently Asked Questions
What is CVE-2026-64217? +
In the Linux kernel, the following vulnerability has been resolved:
netfs: Fix overrun check in netfs_extract_user_iter()
Fix netfs_extract_user_iter() so that if iov_iter_extract_pages() overfills
pages[], then those pages don't get included in the iterator constructed at
the end of the function. If there was an overfill, memory corruption has
already happened.
How do I check if I'm vulnerable to CVE-2026-64217? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.