PT-2026-69788 · Linux+1 · Linux Kernel+1

CVE-2026-68388

·

Published

2026-08-10

·

Updated

2026-08-20

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the smb3 simple fallocate range() function where the system may skip holes when an allocated range returned by the server starts before the current fallocate offset. This results in the skipped hole not being zero-filled despite the operation returning success, which can cause subsequent write operations to that hole to fail with an ENOSPC error. Additionally, a malformed range length could lead to an out-of-bounds read of the zero-buffer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALSA-2026:57251
ALSA-2026:57252
ALSA-2026:57253
ALSA-2026:57254
CVE-2026-68388

Affected Products

Linux Kernel
Rocky Linux