PT-2026-98786 · Linux · Linux

CVE-2026-98124

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
smb/client: invalidate fscache for fallocate range operations
smb3 zero range(), smb3 punch hole(), smb3 insert range(), and smb3 collapse range() modify file contents through server-side range operations. These operations discard the affected page cache, but leave the FS-Cache cookie valid, so a later read may return data cached before the range operation.
Fix this by invalidating FS-Cache after outstanding I/O has completed and before modifying the file on the server.
Run the following as root on a CIFS mount with fsc enabled and an active CacheFiles backend:
bash -c '
    MNT=/mnt/cifs
    FILE="$MNT/repro"

    # Generate four 1 MiB random blocks: [A][B][C][D].
    dd if=/dev/urandom of=/tmp/src bs=1M count=4 status=none

    # Expected contents after zeroing B: [A][zero][C][D].
    cp /tmp/src /tmp/expected
    dd if=/dev/zero of=/tmp/expected bs=1M seek=1 count=1 
        conv=notrunc status=none
    cp /tmp/src "$FILE"

    # Populate FS-Cache, then discard the page cache.
    sync
    echo 1 > /proc/sys/vm/drop caches
    cat "$FILE" > /dev/null
    sync
    echo 1 > /proc/sys/vm/drop caches

    fallocate --zero-range -o 1M -l 1M "$FILE"

    if cmp -s /tmp/expected "$FILE"; then
        echo "readback: OK"
    else
        echo "readback: STALE DATA"
    fi
'
Before this change, the readback differs from /tmp/expected:
readback: STALE DATA
After this change, it matches:
readback: OK
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98124

Affected Products

Linux