PT-2026-98789 · Linux · Linux

CVE-2026-98127

·

Publicado

2026-09-25

·

Atualizado

2026-09-25

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
smb/client: validate new EOF for insert range
smb3 insert range() does not check if the new file size (i size + len) is valid. This allows FALLOC FL INSERT RANGE to bypass RLIMIT FSIZE, exceed s maxbytes, or produce a size outside the loff t range.
Use check add overflow() to calculate the new EOF. Validate it with inode newsize ok() before modifying the file.
Reproducer, using a file on a CIFS mount:
bash -c '
	FILE=/mnt/cifs/repro

	trap "" SIGXFSZ
	ulimit -f 3072		# RLIMIT FSIZE = 3 MiB

	# A regular write is stopped at 3 MiB.
	dd if=/dev/zero of="$FILE" bs=1M count=4 status=none
	stat -c "size after write: %s" "$FILE"

	# Insert 2 MiB into a 2 MiB file.
	truncate -s 2M "$FILE"
	fallocate -i -o 0 -l 2M "$FILE"
	stat -c "size after insert: %s" "$FILE"
'
Before this change, the regular write stops at the 3 MiB limit, but insert range grows the file to 4 MiB:
dd: error writing '/mnt/cifs/repro': File too large
size after write: 3145728
size after insert: 4194304
After this change, insert range also fails at the limit and leaves the 2 MiB file unchanged:
dd: error writing '/mnt/cifs/repro': File too large
size after write: 3145728
fallocate: fallocate failed: File too large
size after insert: 2097152
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98127

Produtos afetados

Linux