Answer in brief
CVE-2026-72366 records a Unknown severity vulnerability in netfs: Fix netfs_create_write_req() to handle async cache object creation. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=7b589a9b45ae32aa9d7bece597490e141198d7a6 <8ab75e445c161c4cb504aa98e20ce1dd1ecd8e9a || >=7b589a9b45ae32aa9d7bece597490e141198d7a6 <1188a9846fadeacf9d1430b528e5217f749d665b || >=7b589a9b45ae32aa9d7bece597490e141198d7a6 <dbd6f56d975b23241b7bbb11bb8f562af548a0aa | 8ab75e445c161c4cb504aa98e20ce1dd1ecd8e9a, 1188a9846fadeacf9d1430b528e5217f749d665b, dbd6f56d975b23241b7bbb11bb8f562af548a0aa |
| Linux/Linuxgeneric | 6.11 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix netfs_create_write_req() to handle async cache object creation netfs_create_write_req() will skip caching if the fscache cookie is disabled, but this is a problem because async cache object creation might not have got far enough yet that has been enabled - thereby causing the call to fscache_begin_write_operation() to be skipped. Fix this by removing the checks on the cookie and delegating this to fscache_begin_write_operation().
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-72366 records a Unknown severity vulnerability in netfs: Fix netfs_create_write_req() to handle async cache object creation. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=7b589a9b45ae32aa9d7bece597490e141198d7a6 <8ab75e445c161c4cb504aa98e20ce1dd1ecd8e9a || >=7b589a9b45ae32aa9d7bece597490e141198d7a6 <1188a9846fadeacf9d1430b528e5217f749d665b || >=7b589a9b45ae32aa9d7bece597490e141198d7a6 <dbd6f56d975b23241b7bbb11bb8f562af548a0aa | 8ab75e445c161c4cb504aa98e20ce1dd1ecd8e9a, 1188a9846fadeacf9d1430b528e5217f749d665b, dbd6f56d975b23241b7bbb11bb8f562af548a0aa |
| Linux/Linuxgeneric | 6.11 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix netfs_create_write_req() to handle async cache object creation netfs_create_write_req() will skip caching if the fscache cookie is disabled, but this is a problem because async cache object creation might not have got far enough yet that has been enabled - thereby causing the call to fscache_begin_write_operation() to be skipped. Fix this by removing the checks on the cookie and delegating this to fscache_begin_write_operation().
Quoted source text, attributed separately from HOL analysis.