-

CVE-2026-98126

smb/client: validate new EOF for zero range

In the Linux kernel, the following vulnerability has been resolved:

smb/client: validate new EOF for zero range

When FALLOC_FL_ZERO_RANGE is used without FALLOC_FL_KEEP_SIZE,
smb3_zero_range() may extend EOF without checking RLIMIT_FSIZE, allowing
the file to grow beyond the caller's file-size limit.

Fix this by calling inode_newsize_ok() before sending the zero-range
request when the operation would extend EOF.

Reproducer, using a file on a CIFS mount:

	bash -c '
	        FILE=/mnt/cifs/repro

	        trap "" SIGXFSZ
	        ulimit -f 3072

	        truncate -s 2M "$FILE"
	        fallocate --zero-range -o 0 -l 4M "$FILE"
	        echo "fallocate rc=$?"
	        stat -c "file size=%s" "$FILE"
	'

Before this change, the operation succeeds despite the 3 MiB limit:

	fallocate rc=0
	file size=4194304

After this change, fallocate fails and leaves the file at 2 MiB.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 72c419d9b073628d3b5b0b2fc787b724f1a8c726
Version < 3673f057b64abfa957e8ae84448db69369a5091a
Status affected
Version 72c419d9b073628d3b5b0b2fc787b724f1a8c726
Version < 06a4f9049cb6dc319bceec2dc813ba89add8b828
Status affected
Version 72c419d9b073628d3b5b0b2fc787b724f1a8c726
Version < f320ca20c273a26cd779bdb2b2e4b076a95c76f6
Status affected
Version 72c419d9b073628d3b5b0b2fc787b724f1a8c726
Version < 88972e35750792e717af287dc71f42a03b5cbce4
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.1
Status affected
Version 0
Version < 5.1
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.055
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/3673f057b64abfa957e8ae84448db69369a5091a
https://git.kernel.org/stable/c/06a4f9049cb6dc319bceec2dc813ba89add8b828
https://git.kernel.org/stable/c/f320ca20c273a26cd779bdb2b2e4b076a95c76f6
https://git.kernel.org/stable/c/88972e35750792e717af287dc71f42a03b5cbce4