7.1
CVE-2026-89640
- EPSS 0.13%
- Veröffentlicht 11.09.2026 19:45:33
- Zuletzt bearbeitet 14.09.2026 13:19:16
- Erkennungen
cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0
In the Linux kernel, the following vulnerability has been resolved:
cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0
With len == 0 (clone to EOF), the effective length is computed as:
len = src_inode->i_size - off;
If off > i_size, this is a negative loff_t, corrupting the ByteCount
in the FSCTL_DUPLICATE_EXTENTS_TO_FILE request and inverting the range
in filemap_write_and_wait_range(). The existing off >= i_size check
fires only after the ioctl has already been sent.
Snapshot i_size_read() once for both the bounds check and the length
calculation, eliminating the TOCTOU and 32-bit torn-read risk. Reject
off > src_size with -EINVAL. Treat off == src_size as a no-op,
consistent with __generic_remap_file_range_prep().Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
04b38d601239b4d9be641b412cf4b7456a041c67
Version <
f3d1ae1e6bc4a9f559185b6e7bd2b6375ec2fdd4
Status
affected
Version
04b38d601239b4d9be641b412cf4b7456a041c67
Version <
7f62817fe049b0f3652518c1ba72631ec1e0a322
Status
affected
Version
04b38d601239b4d9be641b412cf4b7456a041c67
Version <
b098f5e5858797827666e6cd73033f52fc39b5f6
Status
affected
Version
04b38d601239b4d9be641b412cf4b7456a041c67
Version <
c2a0dcb5a7a1516aa6eb6d5cedca6a8e76527028
Status
affected
Version
04b38d601239b4d9be641b412cf4b7456a041c67
Version <
b057ca17b656345d04669cb87f2aff9b31d873db
Status
affected
Version
04b38d601239b4d9be641b412cf4b7456a041c67
Version <
6c322f5cf7476ded7a9a20f7be72462065a03c68
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
4.5
Status
affected
Version
0
Version <
4.5
Status
unaffected
Version <=
6.1.*
Version
6.1.188
Status
unaffected
Version <=
6.6.*
Version
6.6.157
Status
unaffected
Version <=
6.12.*
Version
6.12.109
Status
unaffected
Version <=
6.18.*
Version
6.18.50
Status
unaffected
Version <=
7.2.*
Version
7.2.4
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.025 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.1 | 1.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
|
https://git.kernel.org/stable/c/b098f5e5858797827666e6cd73033f52fc39b5f6
https://git.kernel.org/stable/c/c2a0dcb5a7a1516aa6eb6d5cedca6a8e76527028
https://git.kernel.org/stable/c/b057ca17b656345d04669cb87f2aff9b31d873db
https://git.kernel.org/stable/c/6c322f5cf7476ded7a9a20f7be72462065a03c68
https://git.kernel.org/stable/c/7f62817fe049b0f3652518c1ba72631ec1e0a322
https://git.kernel.org/stable/c/f3d1ae1e6bc4a9f559185b6e7bd2b6375ec2fdd4