{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89639","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.740Z","datePublished":"2026-09-11T19:45:32.532Z","dateUpdated":"2026-09-13T06:32:19.311Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:32:19.311Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: use cifs_invalidate_cache() in cifs_do_truncate() for O_TRUNC\n\ncifs_do_truncate() is invoked from cifs_open() without i_rwsem, so it\ncannot use cifs_resize_file_locked() to perform a proper fscache cookie\nresize.  Instead, add cifs_invalidate_cache() after cifs_setsize().\n\ncifs_invalidate_cache() calls fscache_invalidate(), which works without\nholding i_rwsem: it unconditionally increments inval_counter and sets\nFSCACHE_COOKIE_NO_DATA_TO_READ, ensuring that stale cached data is not\nserved once the cookie is later activated by fscache_use_cookie().\nTruncation to zero leaves no valid cached data, making invalidation the\ncorrect semantic here."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":7.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - cifs_do_truncate() runs from cifs_open() on the SMB client during a local open/openat with O_TRUNC on a mounted CIFS share (fs/smb/client/), not from ksmbd/nfsd or demux-thread packet parsing; a remote SMB peer cannot invoke this path.\nAC:L - A write-capable open with O_TRUNC deterministically skips fscache invalidation, then the same cifs_open() activates the cookie via fscache_use_cookie(); the attacker can also hold another fd so the cookie is already active, with no race or layout outside their control.\nPR:L - O_TRUNC requires only MAY_WRITE on the target inode, which an ordinary local user has on an already-mounted CIFS share; no init-namespace root, CAP_SYS_ADMIN, or user-namespace mount of CIFS is needed.\nUI:N - The attacker issues open(O_TRUNC) and follow-on reads/writes themselves; on common fstab/autofs/CIFS-home deployments with the fsc option already set, no other user must mount the share or open the file.\nS:U - Stale data stays within the local CIFS client's fscache and the same SMB file's contents; this is not a VM escape, IOMMU bypass, or other cross-authority boundary crossing.\nC:H - After O_TRUNC the cookie is activated without FSCACHE_COOKIE_NO_DATA_TO_READ, so later reads (including holes after a size-extending write) can return the full previously truncated file contents that should have been discarded.\nI:H - The same stale cookie presents discarded bytes as current file data and can persist them to the SMB server via netfs read-modify-write/writeback, fully replacing zeros or newly written contents on that file.\nA:N - The flaw is fscache coherency only; it does not oops, panic, deadlock, or exhaust kernel resources, so host availability is unaffected."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/file.c"],"versions":[{"version":"efbcecdecefc26fa062c0e8210533ccad7d6bd4a","lessThan":"8b9b10fe5b8b492b27b9f4546742ea541a650213","status":"affected","versionType":"git"},{"version":"fa724e235cfdb0fb0bb427d0f9dfe864ae27403e","lessThan":"81fc3868a7f726980ff845c1d0d271051e5f0f45","status":"affected","versionType":"git"},{"version":"fa724e235cfdb0fb0bb427d0f9dfe864ae27403e","lessThan":"364b183230586a62660a7280c1eb20138338eeb5","status":"affected","versionType":"git"},{"version":"6838bcac954487cc0a3c8a4ee1b3a3a30e244dc9","status":"affected","versionType":"git"},{"version":"75640976cf474eb41682a13f2dbe9534ac26ca50","status":"affected","versionType":"git"},{"version":"3513f3931c579ba2a715784c6dedc59e0d9282ee","status":"affected","versionType":"git"},{"version":"6.18.44","lessThan":"6.18.50","status":"affected","versionType":"semver"},{"version":"6.12.105","lessThan":"6.13","status":"affected","versionType":"semver"},{"version":"7.1.8","lessThan":"7.2","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/file.c"],"versions":[{"version":"7.2","status":"affected"},{"version":"0","lessThan":"7.2","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18.44","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.2","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.2","versionEndExcluding":"7.3-rc1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12.105"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.1.8"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/8b9b10fe5b8b492b27b9f4546742ea541a650213"},{"url":"https://git.kernel.org/stable/c/81fc3868a7f726980ff845c1d0d271051e5f0f45"},{"url":"https://git.kernel.org/stable/c/364b183230586a62660a7280c1eb20138338eeb5"}],"title":"cifs: use cifs_invalidate_cache() in cifs_do_truncate() for O_TRUNC","x_generator":{"engine":"bippy-1.2.0"}}}}