CVE-2026-98126

Summary

In the Linux kernel, the following vulnerability has been resolved:

smb/client: validate new EOF for zero range

When FALLOC_FL_ZERO_RANGE is used without FALLOC_FL_KEEP_SIZE, smb3_zero_range() may extend EOF without checking RLIMIT_FSIZE, allowing the file to grow beyond the caller's file-size limit.

Fix this by calling inode_newsize_ok() before sending the zero-range request when the operation would extend EOF.

Reproducer, using a file on a CIFS mount:

bash -c '
        FILE=/mnt/cifs/repro

        trap "" SIGXFSZ
        ulimit -f 3072

        truncate -s 2M "$FILE"
        fallocate --zero-range -o 0 -l 4M "$FILE"
        echo "fallocate rc=$?"
        stat -c "file size=%s" "$FILE"
'

Before this change, the operation succeeds despite the 3 MiB limit:

fallocate rc=0
file size=4194304

After this change, fallocate fails and leaves the file at 2 MiB.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux72c419d9b073628d3b5b0b2fc787b724f1a8c726 < 3673f057b64abfa957e8ae84448db69369a5091aaffected
LinuxLinux72c419d9b073628d3b5b0b2fc787b724f1a8c726 < 06a4f9049cb6dc319bceec2dc813ba89add8b828affected
LinuxLinux72c419d9b073628d3b5b0b2fc787b724f1a8c726 < f320ca20c273a26cd779bdb2b2e4b076a95c76f6affected
LinuxLinux72c419d9b073628d3b5b0b2fc787b724f1a8c726 < 88972e35750792e717af287dc71f42a03b5cbce4affected
LinuxLinux5.1affected
LinuxLinux0 < 5.1unaffected
LinuxLinux6.12.111 <= 6.12.*unaffected
LinuxLinux6.18.53 <= 6.18.*unaffected
LinuxLinux7.2.7 <= 7.2.*unaffected
LinuxLinux7.3-rc2 <= *unaffected

Weaknesses

References