๐Ÿ” CVE Alert

CVE-2026-98127

UNKNOWN 0.0

smb/client: validate new EOF for insert range

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: smb/client: validate new EOF for insert range smb3_insert_range() does not check if the new file size (i_size + len) is valid. This allows FALLOC_FL_INSERT_RANGE to bypass RLIMIT_FSIZE, exceed s_maxbytes, or produce a size outside the loff_t range. Use check_add_overflow() to calculate the new EOF. Validate it with inode_newsize_ok() before modifying the file. Reproducer, using a file on a CIFS mount: bash -c ' FILE=/mnt/cifs/repro trap "" SIGXFSZ ulimit -f 3072 # RLIMIT_FSIZE = 3 MiB # A regular write is stopped at 3 MiB. dd if=/dev/zero of="$FILE" bs=1M count=4 status=none stat -c "size after write: %s" "$FILE" # Insert 2 MiB into a 2 MiB file. truncate -s 2M "$FILE" fallocate -i -o 0 -l 2M "$FILE" stat -c "size after insert: %s" "$FILE" ' Before this change, the regular write stops at the 3 MiB limit, but insert range grows the file to 4 MiB: dd: error writing '/mnt/cifs/repro': File too large size after write: 3145728 size after insert: 4194304 After this change, insert range also fails at the limit and leaves the 2 MiB file unchanged: dd: error writing '/mnt/cifs/repro': File too large size after write: 3145728 fallocate: fallocate failed: File too large size after insert: 2097152

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
7fe6fe95b936084dce6eedcc2cccadf96eafae73 < 7c2c69045aa76ccaa7f16f1478eb312130ce4951 7fe6fe95b936084dce6eedcc2cccadf96eafae73 < bc7602b9082ef195d913c4c16fa9853dd262333e 7fe6fe95b936084dce6eedcc2cccadf96eafae73 < f8cbfe3a3fcee7d991fd223f660f3e5df13221cf 7fe6fe95b936084dce6eedcc2cccadf96eafae73 < 1519dc88c87f5346dae0464d7d6da1b6bf1f6e8e
Linux / Linux
5.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/7c2c69045aa76ccaa7f16f1478eb312130ce4951 git.kernel.org: https://git.kernel.org/stable/c/bc7602b9082ef195d913c4c16fa9853dd262333e git.kernel.org: https://git.kernel.org/stable/c/f8cbfe3a3fcee7d991fd223f660f3e5df13221cf git.kernel.org: https://git.kernel.org/stable/c/1519dc88c87f5346dae0464d7d6da1b6bf1f6e8e