Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-64359

Published Jul 25, 2026 EPSS 0.18% (7th pctl)

Overview

CVE-2026-64359 is a known-severity vulnerability. It was published on July 25, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers

Syzbot reported a hung task in nilfs_transaction_begin() where multiple

tasks performing chmod() on a nilfs2 mount blocked for over 143 seconds

waiting to acquire ns_segctor_sem for read:

INFO: task syz.0.17:5918 blocked for more than 143 seconds.

Call Trace:

schedule+0x164/0x360

rwsem_down_read_slowpath+0x6d9/0x940

down_read+0x99/0x2e0

nilfs_transaction_begin+0x364/0x710 fs/nilfs2/segment.c:221

nilfs_setattr+0x124/0x2c0 fs/nilfs2/inode.c:921

notify_change+0xc1a/0xf40

chmod_common+0x273/0x4a0

do_fchmodat+0x12d/0x230

The writer holding ns_segctor_sem was a concurrent

NILFS_IOCTL_CLEAN_SEGMENTS caller, stuck inside printk while emitting

per-element warnings from nilfs_sufile_updatev():

__nilfs_msg+0x373/0x450 fs/nilfs2/super.c:78

nilfs_sufile_updatev+0x21c/0x6d0 fs/nilfs2/sufile.c:186

nilfs_sufile_freev fs/nilf

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-64359?

CVE-2026-64359 is a known-severity vulnerability. It was published on July 25, 2026.

How severe is CVE-2026-64359?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-64359?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-64359?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-64359 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.