« Volver al listado

CVE-2026-68388

Estado: RecibidaCrítica (9.8)—

In the Linux kernel, the following vulnerability has been resolved:

smb/client: handle overlapping allocated ranges in fallocate

smb3_simple_fallocate_range() can skip holes when an allocated range returned by the server starts before the current fallocate offset. The skipped hole is not zero-filled, but fallocate still returns success. A later write to that hole may therefore fail with ENOSPC.

The function queries allocated ranges so that it can preserve existing contents and write zeroes only into holes. However, the server may return a range that starts before the current fallocate offset.

For example, assume the fallocate request is [100, 400) and the only allocated range returned by the server is [0, 200):

Leer descripción completaMostrar menos

The current code adds the full server range length, 200, to the current offset 100 and moves to 300. As a result, the hole in [200, 300) is skipped without being zero-filled.

Fix this by advancing only over the part of the allocated range that overlaps the current fallocate offset. Ignore ranges that end before the current offset and reject ranges whose end offset overflows.

This also prevents a malformed range length from causing an out-of-bounds zero-buffer read.

Detalles técnicos trazas, registros y código del informe original
        Request:      [100, 400)
        Server range: [  0, 200)  allocated

        Correct:
        [100, 200)    allocated data, skip
        [200, 400)    hole, zero-fill

        Current:
        [100, 300)    skipped
        [300, 400)    zero-filled afterwards

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad en kernel Linux remota (AV:N, PR:N, UI:N). Atacante remoto explota fallocate con rangos superpuestos causando DoS (ENOSPC) y corrupción de datos.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-68388",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "c406bb9ece6ef63721daab106f132ff4b4234e81",
              "lessThan": "aeb58a4eb39a7ff4d7782b4f4ada0fda5e0675d2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "966a3cb7c7db786452a87afdc3b48858fc4d4d6b",
              "lessThan": "01719883235507b1585e4c51e320d9a7113dc698",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "966a3cb7c7db786452a87afdc3b48858fc4d4d6b",
              "lessThan": "f47c7277c03a636fcc3a57969f2dc09567b3c050",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "966a3cb7c7db786452a87afdc3b48858fc4d4d6b",
              "lessThan": "437637f5ff3f573b2edf8571de91fb00a21eb4e6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "966a3cb7c7db786452a87afdc3b48858fc4d4d6b",
              "lessThan": "377fe3e583e46369ee1004d5cfe12271d6589a68",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "966a3cb7c7db786452a87afdc3b48858fc4d4d6b",
              "lessThan": "7e08ab7a061b17ac1989a225c6afb53f44a86808",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "966a3cb7c7db786452a87afdc3b48858fc4d4d6b",
              "lessThan": "a4a09e5142835633fffbde68bd0a039ba4d4bf97",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "966a3cb7c7db786452a87afdc3b48858fc4d4d6b",
              "lessThan": "b09ae45d85dc816987a71db9eebc54b0ae288e94",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2f9f4a2d0e6fcf0673ed51195e06e47abe966900",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5e397c943424de94879830e72c95f2679e297a76",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.10.50",
              "lessThan": "5.10.265",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.12.17",
              "lessThan": "5.13",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.13.2",
              "lessThan": "5.14",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "fs/smb/client/smb2ops.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.14"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.14",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.265",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.216",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.183",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.148",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.101",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.42",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/smb/client/smb2ops.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-10T13:20:32.060",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/01719883235507b1585e4c51e320d9a7113dc698",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/377fe3e583e46369ee1004d5cfe12271d6589a68",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/437637f5ff3f573b2edf8571de91fb00a21eb4e6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7e08ab7a061b17ac1989a225c6afb53f44a86808",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a4a09e5142835633fffbde68bd0a039ba4d4bf97",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/aeb58a4eb39a7ff4d7782b4f4ada0fda5e0675d2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b09ae45d85dc816987a71db9eebc54b0ae288e94",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f47c7277c03a636fcc3a57969f2dc09567b3c050",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb/client: handle overlapping allocated ranges in fallocate\n\nsmb3_simple_fallocate_range() can skip holes when an allocated range\nreturned by the server starts before the current fallocate offset. The\nskipped hole is not zero-filled, but fallocate still returns success. A\nlater write to that hole may therefore fail with ENOSPC.\n\nThe function queries allocated ranges so that it can preserve existing\ncontents and write zeroes only into holes. However, the server may return\na range that starts before the current fallocate offset.\n\nFor example, assume the fallocate request is [100, 400) and the only\nallocated range returned by the server is [0, 200):\n\n        Request:      [100, 400)\n        Server range: [  0, 200)  allocated\n\n        Correct:\n        [100, 200)    allocated data, skip\n        [200, 400)    hole, zero-fill\n\n        Current:\n        [100, 300)    skipped\n        [300, 400)    zero-filled afterwards\n\nThe current code adds the full server range length, 200, to the current\noffset 100 and moves to 300. As a result, the hole in [200, 300) is\nskipped without being zero-filled.\n\nFix this by advancing only over the part of the allocated range that\noverlaps the current fallocate offset.  Ignore ranges that end before the\ncurrent offset and reject ranges whose end offset overflows.\n\nThis also prevents a malformed range length from causing an out-of-bounds\nzero-buffer read."
    }
  ],
  "lastModified": "2026-08-19T17:20:47.397",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}