In the Linux kernel, the following vulnerability has been resolved: libfs: set SB_I_NOEXEC and SB_I_NODEV by default in init_pseudo() Since commit… (CVE-2026-64596)
A vulnerability in the Linux kernel related to pseudo-filesystems was resolved by setting the SB_I_NOEXEC and SB_I_NODEV flags by default in the init_pseudo() function. This change prevents executable memory mappings of pseudo-filesystem file descriptors, such as dma-buf, which previously triggered warnings and could violate expected kernel invariants. The fix ensures that attempts to execute mappings from these pseudo-filesystems fail with an appropriate error, enforcing security constraints.
AI Analysis
Technical Summary
The Linux kernel vulnerability addressed involves the handling of pseudo-filesystems initialized by init_pseudo(). Prior to the fix, pseudo-filesystems did not have the SB_I_NOEXEC flag set by default, causing warnings when anonymous-inode files backed by dma-buf were mmap'd with executable permissions under CONFIG_DEBUG_VFS=y. The patch sets SB_I_NOEXEC and SB_I_NODEV flags by default in init_pseudo(), ensuring that executable mappings of pseudo-filesystem file descriptors fail with -EPERM, maintaining kernel security invariants. This change prevents misuse of executable mappings on pseudo-filesystems that are not path-reachable and enforces expected behavior without affecting in-tree callers, which do not map these files executable.
Potential Impact
The vulnerability could allow executable memory mappings of pseudo-filesystem file descriptors that should not be executable, potentially violating kernel security assumptions. The fix enforces that such mappings fail, preventing unauthorized executable mappings. No known in-tree callers perform executable mappings of these pseudo-filesystems, and no known exploits are reported in the wild. The impact is primarily on kernel integrity and enforcement of expected behavior for pseudo-filesystems.
Mitigation Recommendations
The vulnerability has been resolved by setting SB_I_NOEXEC and SB_I_NODEV flags by default in the init_pseudo() function in the Linux kernel. Users should update to a kernel version that includes this fix. Since this is a kernel-level change, applying the official kernel update from the vendor or distribution is the recommended remediation. Patch status is not explicitly stated but the fix is committed in the kernel source. Check the vendor or distribution advisory for the exact fixed version and update accordingly.
In the Linux kernel, the following vulnerability has been resolved: libfs: set SB_I_NOEXEC and SB_I_NODEV by default in init_pseudo() Since commit… (CVE-2026-64596)
Description
A vulnerability in the Linux kernel related to pseudo-filesystems was resolved by setting the SB_I_NOEXEC and SB_I_NODEV flags by default in the init_pseudo() function. This change prevents executable memory mappings of pseudo-filesystem file descriptors, such as dma-buf, which previously triggered warnings and could violate expected kernel invariants. The fix ensures that attempts to execute mappings from these pseudo-filesystems fail with an appropriate error, enforcing security constraints.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel vulnerability addressed involves the handling of pseudo-filesystems initialized by init_pseudo(). Prior to the fix, pseudo-filesystems did not have the SB_I_NOEXEC flag set by default, causing warnings when anonymous-inode files backed by dma-buf were mmap'd with executable permissions under CONFIG_DEBUG_VFS=y. The patch sets SB_I_NOEXEC and SB_I_NODEV flags by default in init_pseudo(), ensuring that executable mappings of pseudo-filesystem file descriptors fail with -EPERM, maintaining kernel security invariants. This change prevents misuse of executable mappings on pseudo-filesystems that are not path-reachable and enforces expected behavior without affecting in-tree callers, which do not map these files executable.
Potential Impact
The vulnerability could allow executable memory mappings of pseudo-filesystem file descriptors that should not be executable, potentially violating kernel security assumptions. The fix enforces that such mappings fail, preventing unauthorized executable mappings. No known in-tree callers perform executable mappings of these pseudo-filesystems, and no known exploits are reported in the wild. The impact is primarily on kernel integrity and enforcement of expected behavior for pseudo-filesystems.
Mitigation Recommendations
The vulnerability has been resolved by setting SB_I_NOEXEC and SB_I_NODEV flags by default in the init_pseudo() function in the Linux kernel. Users should update to a kernel version that includes this fix. Since this is a kernel-level change, applying the official kernel update from the vendor or distribution is the recommended remediation. Patch status is not explicitly stated but the fix is committed in the kernel source. Check the vendor or distribution advisory for the exact fixed version and update accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-99j8-6mjv-5hff
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-64596"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a74cfa0bf8831d5391b0774
Added to database: 08/06/2026, 18:17:04 UTC
Last enriched: 08/06/2026, 19:11:53 UTC
Last updated: 08/07/2026, 00:41:15 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.