« Volver al listado

CVE-2026-90096

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

fuse: invalidate the correct range after O_APPEND direct write

fuse_direct_write_iter() captures pos before generic_write_checks(), which moves ki_pos to EOF for O_APPEND writes:

The post-write invalidation targets a stale range instead of the actual written range at EOF.

This can cause data inconsistency when the file size is not page-aligned. The tail page straddling EOF has a valid portion before EOF that concurrent readers can fault back in during the DIO write window:

Fix by reading pos back from iocb->ki_pos after generic_write_checks(), as generic_file_direct_write() does.

Leer descripción completaMostrar menos

Also fix a typo in the comment ("may have" -> "may have competed").

Detalles técnicos trazas, registros y código del informe original
  fuse_direct_write_iter()
  {
      pos = iocb->ki_pos;           /* 0 (user-supplied)       */
      generic_write_checks();       /* ki_pos -> EOF           */
      fuse_direct_io();             /* writes at EOF, correct  */
      invalidate(pos, pos + res);   /* [0, res) -- wrong       */
  }

  Tail page (file size X not page-aligned):

    page_start         X (EOF)   page_end
    |--- valid data ----|-- stale --|

  CPU0 (O_APPEND DIO writer)    CPU1 (buffered reader)
  --------------------------    ----------------------
  invalidate [X, X+len)
    tail page evicted
  FUSE_WRITE in flight ...
                                read [page_start, X)
                                  tail page re-faulted
                                  [X, page_end) = stale
  FUSE_WRITE completes
  i_size = X + len
  invalidate [0, len)  <- WRONG
    tail page still cached
                                read [X, X+len)
                                  hits stale tail page
                                  returns old data

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90096",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2b0408d0284f4ff376cf5610fa8c9905e93c2541",
              "lessThan": "833963069adf86dcbdffd4e7d7b3171f95070b77",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2b0408d0284f4ff376cf5610fa8c9905e93c2541",
              "lessThan": "26d7e1f5c407b5859122b5cd47d7ebbf4b4c1cd2",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/fuse/file.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.2"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.2",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/fuse/file.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:01.233",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/26d7e1f5c407b5859122b5cd47d7ebbf4b4c1cd2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/833963069adf86dcbdffd4e7d7b3171f95070b77",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: invalidate the correct range after O_APPEND direct write\n\nfuse_direct_write_iter() captures pos before generic_write_checks(),\nwhich moves ki_pos to EOF for O_APPEND writes:\n\n  fuse_direct_write_iter()\n  {\n      pos = iocb->ki_pos;           /* 0 (user-supplied)       */\n      generic_write_checks();       /* ki_pos -> EOF           */\n      fuse_direct_io();             /* writes at EOF, correct  */\n      invalidate(pos, pos + res);   /* [0, res) -- wrong       */\n  }\n\nThe post-write invalidation targets a stale range instead of the\nactual written range at EOF.\n\nThis can cause data inconsistency when the file size is not\npage-aligned.  The tail page straddling EOF has a valid portion\nbefore EOF that concurrent readers can fault back in during the\nDIO write window:\n\n  Tail page (file size X not page-aligned):\n\n    page_start         X (EOF)   page_end\n    |--- valid data ----|-- stale --|\n\n  CPU0 (O_APPEND DIO writer)    CPU1 (buffered reader)\n  --------------------------    ----------------------\n  invalidate [X, X+len)\n    tail page evicted\n  FUSE_WRITE in flight ...\n                                read [page_start, X)\n                                  tail page re-faulted\n                                  [X, page_end) = stale\n  FUSE_WRITE completes\n  i_size = X + len\n  invalidate [0, len)  <- WRONG\n    tail page still cached\n                                read [X, X+len)\n                                  hits stale tail page\n                                  returns old data\n\nFix by reading pos back from iocb->ki_pos after generic_write_checks(),\nas generic_file_direct_write() does.\n\nAlso fix a typo in the comment (\"may have\" -> \"may have competed\")."
    }
  ],
  "lastModified": "2026-09-17T17:17:01.233",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}