« Volver al listado

CVE-2026-89639

Estado: RecibidaAlta (7.1)—

In the Linux kernel, the following vulnerability has been resolved:

cifs: use cifs_invalidate_cache() in cifs_do_truncate() for O_TRUNC

cifs_do_truncate() is invoked from cifs_open() without i_rwsem, so it cannot use cifs_resize_file_locked() to perform a proper fscache cookie resize. Instead, add cifs_invalidate_cache() after cifs_setsize().

cifs_invalidate_cache() calls fscache_invalidate(), which works without holding i_rwsem: it unconditionally increments inval_counter and sets FSCACHE_COOKIE_NO_DATA_TO_READ, ensuring that stale cached data is not served once the cookie is later activated by fscache_use_cookie(). Truncation to zero leaves no valid cached data, making invalidation the correct semantic here.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Acceso local con privilegios (PR:L) sin interacción permite escalada mediante vulnerabilidad en gestión de caché de CIFS. Lectura de datos confidenciales (C:H) desde archivos truncados por invalidación de caché.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89639",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "efbcecdecefc26fa062c0e8210533ccad7d6bd4a",
              "lessThan": "8b9b10fe5b8b492b27b9f4546742ea541a650213",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fa724e235cfdb0fb0bb427d0f9dfe864ae27403e",
              "lessThan": "81fc3868a7f726980ff845c1d0d271051e5f0f45",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fa724e235cfdb0fb0bb427d0f9dfe864ae27403e",
              "lessThan": "364b183230586a62660a7280c1eb20138338eeb5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6838bcac954487cc0a3c8a4ee1b3a3a30e244dc9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "75640976cf474eb41682a13f2dbe9534ac26ca50",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3513f3931c579ba2a715784c6dedc59e0d9282ee",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.18.44",
              "lessThan": "6.18.50",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.12.105",
              "lessThan": "6.13",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "7.1.8",
              "lessThan": "7.2",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "fs/smb/client/file.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.2"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.2",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.50",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/smb/client/file.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:19:49.617",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/364b183230586a62660a7280c1eb20138338eeb5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/81fc3868a7f726980ff845c1d0d271051e5f0f45",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8b9b10fe5b8b492b27b9f4546742ea541a650213",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: use cifs_invalidate_cache() in cifs_do_truncate() for O_TRUNC\n\ncifs_do_truncate() is invoked from cifs_open() without i_rwsem, so it\ncannot use cifs_resize_file_locked() to perform a proper fscache cookie\nresize.  Instead, add cifs_invalidate_cache() after cifs_setsize().\n\ncifs_invalidate_cache() calls fscache_invalidate(), which works without\nholding i_rwsem: it unconditionally increments inval_counter and sets\nFSCACHE_COOKIE_NO_DATA_TO_READ, ensuring that stale cached data is not\nserved once the cookie is later activated by fscache_use_cookie().\nTruncation to zero leaves no valid cached data, making invalidation the\ncorrect semantic here."
    }
  ],
  "lastModified": "2026-09-13T07:17:29.130",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}