CVE-2026-97610: Linux

EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix uninitialized return value in netfs_unbuffered_write() If preparation of the first subrequest fails, netfs_unbuffered_write() exits its loop before ret is initialized. The empty-iterator check can do the same. For synchronous writes, netfs_unbuffered_write_iter_locked() may then return an unrelated error instead of wreq->error. This is reachable through CIFS if cifs_prepare_write() fails to reopen the file or obtain credits. Initialize ret to 0 so the caller returns wreq->error if no data was written, or the number of bytes already written otherwise. Found with Clang's -Wconditional-uninitialized.

Affected products

  • Linux Linux: from 6.18.17, before 6.18.53 (fixed in 6.18.53); from 6.19.7, before 6.20 (fixed in 6.20); from 7.0, before 7.2.7 (fixed in 7.2.7)

Published 2026-09-25. Last modified 2026-09-25.