Answer in brief
CVE-2026-72132 records a Unknown severity vulnerability in NFS: Charge unstable writes by request size, not folio size. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=0c493b5cf16e28d761b6e77c7c32aa0e7af70813 <a442c258320b689f13d2205eaeeddf8b0e630288 || >=0c493b5cf16e28d761b6e77c7c32aa0e7af70813 <1f646e23372f3444dc5f0bcb5404a49d26756add || >=0c493b5cf16e28d761b6e77c7c32aa0e7af70813 <0ffc032294a29601b1019dba91aa1a930d90df17 || >=0c493b5cf16e28d761b6e77c7c32aa0e7af70813 <a192b6c149c6ea10cc88869accb78165eb454456 || >=0c493b5cf16e28d761b6e77c7c32aa0e7af70813 <27934d02cbeb8a957dd11c985a579e58d30c5270 | a442c258320b689f13d2205eaeeddf8b0e630288, 1f646e23372f3444dc5f0bcb5404a49d26756add, 0ffc032294a29601b1019dba91aa1a930d90df17, a192b6c149c6ea10cc88869accb78165eb454456, 27934d02cbeb8a957dd11c985a579e58d30c5270 |
| Linux/Linuxgeneric | 6.3 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: NFS: Charge unstable writes by request size, not folio size nfs_folio_mark_unstable() and nfs_folio_clear_commit() charge and uncharge NR_WRITEBACK/WB_WRITEBACK by folio_nr_pages(folio) once per *request* added to or removed from a commit list. This is correct only when a folio has a single associated request. When pg_test splits a folio into N sub-folio requests (e.g. pNFS flexfiles striping with a stripe unit smaller than the folio size, or plain wsize-limited splitting), each of the N requests independently charges the whole folio's page count, inflating the accounting by a factor of N per folio. With large folios and small stripe units this reaches multiple orders of magnitude: a 2 MiB folio split into 512 4 KiB requests can charge up to 512x its real size, pushing global dirty+writeback accounting past the system's dirty threshold and forcing every buffered writer on the host into the hard-throttle path, including unrelated in-kernel NFS server threads sharing the box. Charge each request only for the pages it actually covers.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-72132 records a Unknown severity vulnerability in NFS: Charge unstable writes by request size, not folio size. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=0c493b5cf16e28d761b6e77c7c32aa0e7af70813 <a442c258320b689f13d2205eaeeddf8b0e630288 || >=0c493b5cf16e28d761b6e77c7c32aa0e7af70813 <1f646e23372f3444dc5f0bcb5404a49d26756add || >=0c493b5cf16e28d761b6e77c7c32aa0e7af70813 <0ffc032294a29601b1019dba91aa1a930d90df17 || >=0c493b5cf16e28d761b6e77c7c32aa0e7af70813 <a192b6c149c6ea10cc88869accb78165eb454456 || >=0c493b5cf16e28d761b6e77c7c32aa0e7af70813 <27934d02cbeb8a957dd11c985a579e58d30c5270 | a442c258320b689f13d2205eaeeddf8b0e630288, 1f646e23372f3444dc5f0bcb5404a49d26756add, 0ffc032294a29601b1019dba91aa1a930d90df17, a192b6c149c6ea10cc88869accb78165eb454456, 27934d02cbeb8a957dd11c985a579e58d30c5270 |
| Linux/Linuxgeneric | 6.3 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: NFS: Charge unstable writes by request size, not folio size nfs_folio_mark_unstable() and nfs_folio_clear_commit() charge and uncharge NR_WRITEBACK/WB_WRITEBACK by folio_nr_pages(folio) once per *request* added to or removed from a commit list. This is correct only when a folio has a single associated request. When pg_test splits a folio into N sub-folio requests (e.g. pNFS flexfiles striping with a stripe unit smaller than the folio size, or plain wsize-limited splitting), each of the N requests independently charges the whole folio's page count, inflating the accounting by a factor of N per folio. With large folios and small stripe units this reaches multiple orders of magnitude: a 2 MiB folio split into 512 4 KiB requests can charge up to 512x its real size, pushing global dirty+writeback accounting past the system's dirty threshold and forcing every buffered writer on the host into the hard-throttle path, including unrelated in-kernel NFS server threads sharing the box. Charge each request only for the pages it actually covers.
Quoted source text, attributed separately from HOL analysis.