Linux Kernel Vulnerability in SMB Client Operations Affecting File System
CVE-2026-98124

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-98124?

A vulnerability exists in the Linux kernel SMB client operations where server-side range operations fail to invalidate the FS-Cache, leading to potential inconsistencies in data retrieval. Modifications made by functions such as smb3_zero_range, smb3_punch_hole, smb3_insert_range, and smb3_collapse_range can leave outdated cached data available for reads after file modifications. This issue is addressed by ensuring FS-Cache is invalidated promptly after outstanding I/O completes, preventing stale data from being returned. Users are encouraged to apply updates to mitigate this vulnerability.

Affected Version(s)

Linux 31742c5a331766bc7df6b0d525df00c6cd20d5a6 < 93c6e5a8d7c5071d586c1411596d5db5faad22b2

Linux 31742c5a331766bc7df6b0d525df00c6cd20d5a6 < 448ba0ae65ca61064183564d2983c9aa59bd6ba7

Linux 3.17

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.