« Volver al listado

CVE-2026-98124

Estado: En análisisSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

smb/client: invalidate fscache for fallocate range operations

smb3_zero_range(), smb3_punch_hole(), smb3_insert_range(), and smb3_collapse_range() modify file contents through server-side range operations. These operations discard the affected page cache, but leave the FS-Cache cookie valid, so a later read may return data cached before the range operation.

Fix this by invalidating FS-Cache after outstanding I/O has completed and before modifying the file on the server.

Run the following as root on a CIFS mount with fsc enabled and an active CacheFiles backend:

Leer descripción completaMostrar menos

Before this change, the readback differs from /tmp/expected:

After this change, it matches:

Detalles técnicos trazas, registros y código del informe original
        bash -c '
                MNT=/mnt/cifs
                FILE="$MNT/repro"

                # Generate four 1 MiB random blocks: [A][B][C][D].
                dd if=/dev/urandom of=/tmp/src bs=1M count=4 status=none

                # Expected contents after zeroing B: [A][zero][C][D].
                cp /tmp/src /tmp/expected
                dd if=/dev/zero of=/tmp/expected bs=1M seek=1 count=1 \
                        conv=notrunc status=none
                cp /tmp/src "$FILE"

                # Populate FS-Cache, then discard the page cache.
                sync
                echo 1 > /proc/sys/vm/drop_caches
                cat "$FILE" > /dev/null
                sync
                echo 1 > /proc/sys/vm/drop_caches

                fallocate --zero-range -o 1M -l 1M "$FILE"

                if cmp -s /tmp/expected "$FILE"; then
                        echo "readback: OK"
                else
                        echo "readback: STALE DATA"
                fi
        '

        readback: STALE DATA

        readback: OK

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98124",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "31742c5a331766bc7df6b0d525df00c6cd20d5a6",
              "lessThan": "93c6e5a8d7c5071d586c1411596d5db5faad22b2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "31742c5a331766bc7df6b0d525df00c6cd20d5a6",
              "lessThan": "448ba0ae65ca61064183564d2983c9aa59bd6ba7",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/smb/client/smb2ops.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.17"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.17",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/smb/client/smb2ops.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:43.720",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/448ba0ae65ca61064183564d2983c9aa59bd6ba7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/93c6e5a8d7c5071d586c1411596d5db5faad22b2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Undergoing Analysis",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb/client: invalidate fscache for fallocate range operations\n\nsmb3_zero_range(), smb3_punch_hole(), smb3_insert_range(), and\nsmb3_collapse_range() modify file contents through server-side range\noperations. These operations discard the affected page cache, but leave\nthe FS-Cache cookie valid, so a later read may return data cached before\nthe range operation.\n\nFix this by invalidating FS-Cache after outstanding I/O has completed\nand before modifying the file on the server.\n\nRun the following as root on a CIFS mount with fsc enabled and an active\nCacheFiles backend:\n\n        bash -c '\n                MNT=/mnt/cifs\n                FILE=\"$MNT/repro\"\n\n                # Generate four 1 MiB random blocks: [A][B][C][D].\n                dd if=/dev/urandom of=/tmp/src bs=1M count=4 status=none\n\n                # Expected contents after zeroing B: [A][zero][C][D].\n                cp /tmp/src /tmp/expected\n                dd if=/dev/zero of=/tmp/expected bs=1M seek=1 count=1 \\\n                        conv=notrunc status=none\n                cp /tmp/src \"$FILE\"\n\n                # Populate FS-Cache, then discard the page cache.\n                sync\n                echo 1 > /proc/sys/vm/drop_caches\n                cat \"$FILE\" > /dev/null\n                sync\n                echo 1 > /proc/sys/vm/drop_caches\n\n                fallocate --zero-range -o 1M -l 1M \"$FILE\"\n\n                if cmp -s /tmp/expected \"$FILE\"; then\n                        echo \"readback: OK\"\n                else\n                        echo \"readback: STALE DATA\"\n                fi\n        '\n\nBefore this change, the readback differs from /tmp/expected:\n\n        readback: STALE DATA\n\nAfter this change, it matches:\n\n        readback: OK"
    }
  ],
  "lastModified": "2026-09-30T14:10:59.253",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}