GHSA-x5p7-qjx7-h5j9unknown

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix uninitialized...

Published
September 25, 2026
Last Modified
September 25, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

netfs: Fix uninitialized return value in netfs_unbuffered_write()

If preparation of the first subrequest fails, netfs_unbuffered_write() exits its loop before ret is initialized. The empty-iterator check can do the same.

For synchronous writes, netfs_unbuffered_write_iter_locked() may then return an unrelated error instead of wreq->error. This is reachable through CIFS if cifs_prepare_write() fails to reopen the file or obtain credits.

Initialize ret to 0 so the caller returns wreq->error if no data was written, or the number of bytes already written otherwise.

Found with Clang's -Wconditional-uninitialized.

🔗 References (5)