NFS: Charge unstable writes by request size, not folio size
Summary
| CVE | CVE-2026-72132 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-15 06:21:30 UTC |
| Updated | 2026-08-15 06:21:30 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
NFS: Charge unstable writes by request size, not folio size
nfs_folio_mark_unstable() and nfs_folio_clear_commit() charge and
uncharge NR_WRITEBACK/WB_WRITEBACK by folio_nr_pages(folio) once per
*request* added to or removed from a commit list. This is correct only
when a folio has a single associated request. When pg_test splits a
folio into N sub-folio requests (e.g. pNFS flexfiles striping with a
stripe unit smaller than the folio size, or plain wsize-limited
splitting), each of the N requests independently charges the whole
folio's page count, inflating the accounting by a factor of N per
folio. With large folios and small stripe units this reaches multiple
orders of magnitude: a 2 MiB folio split into 512 4 KiB requests can
charge up to 512x its real size, pushing global dirty+writeback
accounting past the system's dirty threshold and forcing every
buffered writer on the host into the hard-throttle path, including
unrelated in-kernel NFS server threads sharing the box.
Charge each request only for the pages it actually covers. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 0c493b5cf16e28d761b6e77c7c32aa0e7af70813 a442c258320b689f13d2205eaeeddf8b0e630288 git |
Not specified |
| CNA |
Linux |
Linux |
affected 0c493b5cf16e28d761b6e77c7c32aa0e7af70813 1f646e23372f3444dc5f0bcb5404a49d26756add git |
Not specified |
| CNA |
Linux |
Linux |
affected 0c493b5cf16e28d761b6e77c7c32aa0e7af70813 0ffc032294a29601b1019dba91aa1a930d90df17 git |
Not specified |
| CNA |
Linux |
Linux |
affected 0c493b5cf16e28d761b6e77c7c32aa0e7af70813 a192b6c149c6ea10cc88869accb78165eb454456 git |
Not specified |
| CNA |
Linux |
Linux |
affected 0c493b5cf16e28d761b6e77c7c32aa0e7af70813 27934d02cbeb8a957dd11c985a579e58d30c5270 git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.3 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.3 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.148 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.97 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.40 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.5 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2-rc3 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/27934d02cbeb8a957dd11c985a579e58d30c5270 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/0ffc032294a29601b1019dba91aa1a930d90df17 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/a192b6c149c6ea10cc88869accb78165eb454456 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/a442c258320b689f13d2205eaeeddf8b0e630288 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/1f646e23372f3444dc5f0bcb5404a49d26756add |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.