« Volver al listado

CVE-2026-93794

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

smb/client: flush dirty data before punching a hole

Punching a hole after a large buffered write may leave the range reported as data. Reproduce it with:

Punching 1 MiB at offset 1 MiB should produce:

Instead, the entire file is reported as data. SEEK_HOLE(0) returns EOF, and SEEK_DATA(1M) returns 1M.

This happens because a dirty folio spanning the punched range can be written back after the punch and refill the hole.

Fix this by flushing and waiting for dirty data in the punched range before invalidating the page cache and issuing FSCTL_SET_ZERO_DATA.

Leer descripción completaMostrar menos

The xfstests generic/539 pass against Samba/ksmbd with this change.

Detalles técnicos trazas, registros y código del informe original
  xfs_io -f \
    -c "pwrite -b 3m -S 0x61 0 3m" \
    -c "fpunch 1m 1m" \
    -c "seek -h 0" \
    -c "seek -d 1m" \
    /mnt/test/repro

  0          1 MiB       2 MiB       3 MiB
  |  DATA    |   HOLE    |   DATA    | EOF

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93794",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "31742c5a331766bc7df6b0d525df00c6cd20d5a6",
              "lessThan": "216e469586057c29409e4ef8311d282388c6e251",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "31742c5a331766bc7df6b0d525df00c6cd20d5a6",
              "lessThan": "6c265aca08155e519a8f6f6071c59dff4f535f70",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "31742c5a331766bc7df6b0d525df00c6cd20d5a6",
              "lessThan": "39562a56cdb515f6635c3e7bfe6629439b18a169",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "31742c5a331766bc7df6b0d525df00c6cd20d5a6",
              "lessThan": "d7d2adcd022baade5cab65ca492ce63421ce3a6e",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/smb/client/smb2ops.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.17"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.17",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/smb/client/smb2ops.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-24T17:17:12.160",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/216e469586057c29409e4ef8311d282388c6e251",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/39562a56cdb515f6635c3e7bfe6629439b18a169",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6c265aca08155e519a8f6f6071c59dff4f535f70",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d7d2adcd022baade5cab65ca492ce63421ce3a6e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb/client: flush dirty data before punching a hole\n\nPunching a hole after a large buffered write may leave the range\nreported as data. Reproduce it with:\n\n  xfs_io -f \\\n    -c \"pwrite -b 3m -S 0x61 0 3m\" \\\n    -c \"fpunch 1m 1m\" \\\n    -c \"seek -h 0\" \\\n    -c \"seek -d 1m\" \\\n    /mnt/test/repro\n\nPunching 1 MiB at offset 1 MiB should produce:\n\n  0          1 MiB       2 MiB       3 MiB\n  |  DATA    |   HOLE    |   DATA    | EOF\n\nInstead, the entire file is reported as data. SEEK_HOLE(0) returns EOF,\nand SEEK_DATA(1M) returns 1M.\n\nThis happens because a dirty folio spanning the punched range can be\nwritten back after the punch and refill the hole.\n\nFix this by flushing and waiting for dirty data in the punched range\nbefore invalidating the page cache and issuing FSCTL_SET_ZERO_DATA.\n\nThe xfstests generic/539 pass against Samba/ksmbd with this change."
    }
  ],
  "lastModified": "2026-10-03T11:17:49.000",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}