CVE-2026-90096
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
fuse: invalidate the correct range after O_APPEND direct write
fuse_direct_write_iter() captures pos before generic_write_checks(), which moves ki_pos to EOF for O_APPEND writes:
fuse_direct_write_iter() { pos = iocb->ki_pos; /* 0 (user-supplied) / generic_write_checks(); / ki_pos -> EOF / fuse_direct_io(); / writes at EOF, correct / invalidate(pos, pos + res); / [0, res) – wrong */ }
The post-write invalidation targets a stale range instead of the actual written range at EOF.
This can cause data inconsistency when the file size is not page-aligned. The tail page straddling EOF has a valid portion before EOF that concurrent readers can fault back in during the DIO write window:
Tail page (file size X not page-aligned):
page_start X (EOF) page_end
|--- valid data ----|-- stale --|
CPU0 (O_APPEND DIO writer) CPU1 (buffered reader)
invalidate [X, X+len) tail page evicted FUSE_WRITE in flight … read [page_start, X) tail page re-faulted [X, page_end) = stale FUSE_WRITE completes i_size = X + len invalidate [0, len) <- WRONG tail page still cached read [X, X+len) hits stale tail page returns old data
Fix by reading pos back from iocb->ki_pos after generic_write_checks(), as generic_file_direct_write() does.
Also fix a typo in the comment ("may have" -> "may have competed").
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 2b0408d0284f4ff376cf5610fa8c9905e93c2541 < 833963069adf86dcbdffd4e7d7b3171f95070b77 | affected |
| Linux | Linux | 2b0408d0284f4ff376cf5610fa8c9905e93c2541 < 26d7e1f5c407b5859122b5cd47d7ebbf4b4c1cd2 | affected |
| Linux | Linux | 7.2 | affected |
| Linux | Linux | 0 < 7.2 | unaffected |
| Linux | Linux | 7.2.6 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/833963069adf86dcbdffd4e7d7b3171f95070b77
- https://git.kernel.org/stable/c/26d7e1f5c407b5859122b5cd47d7ebbf4b4c1cd2
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.