{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90176","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.791Z","datePublished":"2026-09-17T16:07:02.433Z","dateUpdated":"2026-09-18T17:53:36.125Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:53:36.125Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: Do not skip lock checks for single-byte ranges\n\ncheck_lock_range() uses inclusive ranges. Its callers pass the end\noffset as start + length - 1, so start == end represents a valid\nsingle-byte range rather than an empty range.\n\nThe start == end shortcut therefore skips mandatory byte-range lock\nchecks for one-byte reads, writes, copychunk operations and one-byte\ntruncate ranges. A conflicting lock covering that byte is not checked\nand the operation is allowed to proceed.\n\nRemove the shortcut. The truncate size == inode->i_size case is already\nhandled by only calling check_lock_range() when the new size differs\nfrom the current file size."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - The skip is driven by attacker-controlled range length in SMB2 PDUs: smb2_read()/smb2_write() pass Length==1 into ksmbd_vfs_read/write, set_end_of_file_info() passes a 1-byte size change to ksmbd_vfs_truncate(), and FSCTL_SRV_COPYCHUNK Length==1 reaches ksmbd_vfs_copy_file_ranges(); those messages arrive on the ksmbd TCP connection in ksmbd_conn_handler_loop().\nAC:L - Callers pass an inclusive end of start+length-1, so Length==1 makes start==end and the shortcut in check_lock_range() returns 0 before walking ctx->flc_posix; the attacker sets Length, Offset, EndOfFile, or COPYCHUNK Length in the PDU, and the skip is deterministic with no race or uncontrollable layout.\nPR:L - smb2_check_user_session() requires SMB2_SESSION_VALID before SMB2_READ/WRITE/SET_INFO/IOCTL, smb2_get_ksmbd_tcon() requires a tree connect, and the handlers resolve a fid via ksmbd_lookup_fd_slow(); this is not negotiate or session-setup, so an authenticated SMB share user is required.\nUI:N - The attacker, holding their own session, tree connect, and open handle, sends the one-byte SMB2 READ, WRITE, SET_INFO FILE_END_OF_FILE_INFORMATION, or FSCTL_SRV_COPYCHUNK; no other user must mount media or confirm an action.\nS:U - Bypassing check_lock_range() only allows this ksmbd worker to read or write host file bytes that conflicting FL_POSIX locks on flc_posix should have denied; there is no VM escape, IOMMU bypass, or sandbox boundary crossing.\nC:H - ksmbd_vfs_read() and the COPYCHUNK source check skip exclusive F_WRLCK locks belonging to another filp when start==end, so kernel_read() returns that byte; repeating SMB2 READ at chosen offsets discloses every exclusively locked byte of a file the attacker can open.\nI:H - ksmbd_vfs_write(), ksmbd_vfs_truncate() for size==i_size±1, and COPYCHUNK dest checks likewise skip conflicting F_RDLCK/F_WRLCK, so kernel_write() and vfs_truncate() can overwrite locked bytes or change size by one at attacker-chosen offsets.\nA:N - When the shortcut hits, check_lock_range() returns 0 and the existing kernel_read/kernel_write/vfs_truncate path runs normally; the bug does not NULL-deref, BUG, deadlock, or panic, and the ksmbd worker keeps serving."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/server/vfs.c"],"versions":[{"version":"52fcbb92e0d3acfd1448b2a43b6595d540da5295","lessThan":"a89cc145832e81c32199d4ca2e1ea8bd51ed601d","status":"affected","versionType":"git"},{"version":"da29cd197246c85c0473259f1cad897d9d28faea","lessThan":"993e0158331d37c04da18efe551b5e1e35fb3078","status":"affected","versionType":"git"},{"version":"a6f4cfa3783804336491e0edcb250c25f9b59d33","lessThan":"f751d6e39d4c937c45f8fedc66699aa7d2d52288","status":"affected","versionType":"git"},{"version":"571204e4758a528fbd67330bd4b0dfbdafb33dd8","lessThan":"84c2d8e807ac489f5c91769293fb15dfdae8bae8","status":"affected","versionType":"git"},{"version":"5d510ac31626ed157d2182149559430350cf2104","lessThan":"07a9e289ff7edcc004f58952405f8a65c4e37512","status":"affected","versionType":"git"},{"version":"5d510ac31626ed157d2182149559430350cf2104","lessThan":"d40c24634fe077a0dc91fd11fccf44ce12b454d5","status":"affected","versionType":"git"},{"version":"6.1.160","lessThan":"6.1.188","status":"affected","versionType":"semver"},{"version":"6.6.120","lessThan":"6.6.157","status":"affected","versionType":"semver"},{"version":"6.12.64","lessThan":"6.12.110","status":"affected","versionType":"semver"},{"version":"6.18.3","lessThan":"6.18.52","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/server/vfs.c"],"versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1.160","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6.120","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12.64","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18.3","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.19","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.19","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/a89cc145832e81c32199d4ca2e1ea8bd51ed601d"},{"url":"https://git.kernel.org/stable/c/993e0158331d37c04da18efe551b5e1e35fb3078"},{"url":"https://git.kernel.org/stable/c/f751d6e39d4c937c45f8fedc66699aa7d2d52288"},{"url":"https://git.kernel.org/stable/c/84c2d8e807ac489f5c91769293fb15dfdae8bae8"},{"url":"https://git.kernel.org/stable/c/07a9e289ff7edcc004f58952405f8a65c4e37512"},{"url":"https://git.kernel.org/stable/c/d40c24634fe077a0dc91fd11fccf44ce12b454d5"}],"title":"ksmbd: Do not skip lock checks for single-byte ranges","x_generator":{"engine":"bippy-1.2.0"}}}}