CVE-2026-93794
In the Linux kernel, the following vulnerability has been resolved:
smb/client: flush dirty data before punching a hole
Punching a hole after a large buffered write may leave the range reported as data. Reproduce it with:
Punching 1 MiB at offset 1 MiB should produce:
Instead, the entire file is reported as data. SEEK_HOLE(0) returns EOF, and SEEK_DATA(1M) returns 1M.
This happens because a dirty folio spanning the punched range can be written back after the punch and refill the hole.
Fix this by flushing and waiting for dirty data in the punched range before invalidating the page cache and issuing FSCTL_SET_ZERO_DATA.
Leer descripción completaMostrar menos
The xfstests generic/539 pass against Samba/ksmbd with this change.
Detalles técnicos trazas, registros y código del informe original
xfs_io -f \
-c "pwrite -b 3m -S 0x61 0 3m" \
-c "fpunch 1m 1m" \
-c "seek -h 0" \
-c "seek -d 1m" \
/mnt/test/repro
0 1 MiB 2 MiB 3 MiB
| DATA | HOLE | DATA | EOFCVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 5
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-93794",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "31742c5a331766bc7df6b0d525df00c6cd20d5a6",
"lessThan": "216e469586057c29409e4ef8311d282388c6e251",
"versionType": "git"
},
{
"status": "affected",
"version": "31742c5a331766bc7df6b0d525df00c6cd20d5a6",
"lessThan": "6c265aca08155e519a8f6f6071c59dff4f535f70",
"versionType": "git"
},
{
"status": "affected",
"version": "31742c5a331766bc7df6b0d525df00c6cd20d5a6",
"lessThan": "39562a56cdb515f6635c3e7bfe6629439b18a169",
"versionType": "git"
},
{
"status": "affected",
"version": "31742c5a331766bc7df6b0d525df00c6cd20d5a6",
"lessThan": "d7d2adcd022baade5cab65ca492ce63421ce3a6e",
"versionType": "git"
}
],
"programFiles": [
"fs/smb/client/smb2ops.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3.17"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "3.17",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/smb/client/smb2ops.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-24T17:17:12.160",
"references": [
{
"url": "https://git.kernel.org/stable/c/216e469586057c29409e4ef8311d282388c6e251",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/39562a56cdb515f6635c3e7bfe6629439b18a169",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6c265aca08155e519a8f6f6071c59dff4f535f70",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d7d2adcd022baade5cab65ca492ce63421ce3a6e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb/client: flush dirty data before punching a hole\n\nPunching a hole after a large buffered write may leave the range\nreported as data. Reproduce it with:\n\n xfs_io -f \\\n -c \"pwrite -b 3m -S 0x61 0 3m\" \\\n -c \"fpunch 1m 1m\" \\\n -c \"seek -h 0\" \\\n -c \"seek -d 1m\" \\\n /mnt/test/repro\n\nPunching 1 MiB at offset 1 MiB should produce:\n\n 0 1 MiB 2 MiB 3 MiB\n | DATA | HOLE | DATA | EOF\n\nInstead, the entire file is reported as data. SEEK_HOLE(0) returns EOF,\nand SEEK_DATA(1M) returns 1M.\n\nThis happens because a dirty folio spanning the punched range can be\nwritten back after the punch and refill the hole.\n\nFix this by flushing and waiting for dirty data in the punched range\nbefore invalidating the page cache and issuing FSCTL_SET_ZERO_DATA.\n\nThe xfstests generic/539 pass against Samba/ksmbd with this change."
}
],
"lastModified": "2026-10-03T11:17:49.000",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}