{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98126","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.318Z","datePublished":"2026-09-25T10:36:07.797Z","dateUpdated":"2026-09-25T10:36:07.797Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-25T10:36:07.797Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb/client: validate new EOF for zero range\n\nWhen FALLOC_FL_ZERO_RANGE is used without FALLOC_FL_KEEP_SIZE,\nsmb3_zero_range() may extend EOF without checking RLIMIT_FSIZE, allowing\nthe file to grow beyond the caller's file-size limit.\n\nFix this by calling inode_newsize_ok() before sending the zero-range\nrequest when the operation would extend EOF.\n\nReproducer, using a file on a CIFS mount:\n\n\tbash -c '\n\t        FILE=/mnt/cifs/repro\n\n\t        trap \"\" SIGXFSZ\n\t        ulimit -f 3072\n\n\t        truncate -s 2M \"$FILE\"\n\t        fallocate --zero-range -o 0 -l 4M \"$FILE\"\n\t        echo \"fallocate rc=$?\"\n\t        stat -c \"file size=%s\" \"$FILE\"\n\t'\n\nBefore this change, the operation succeeds despite the 3 MiB limit:\n\n\tfallocate rc=0\n\tfile size=4194304\n\nAfter this change, fallocate fails and leaves the file at 2 MiB."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/smb2ops.c"],"versions":[{"version":"72c419d9b073628d3b5b0b2fc787b724f1a8c726","lessThan":"3673f057b64abfa957e8ae84448db69369a5091a","status":"affected","versionType":"git"},{"version":"72c419d9b073628d3b5b0b2fc787b724f1a8c726","lessThan":"06a4f9049cb6dc319bceec2dc813ba89add8b828","status":"affected","versionType":"git"},{"version":"72c419d9b073628d3b5b0b2fc787b724f1a8c726","lessThan":"f320ca20c273a26cd779bdb2b2e4b076a95c76f6","status":"affected","versionType":"git"},{"version":"72c419d9b073628d3b5b0b2fc787b724f1a8c726","lessThan":"88972e35750792e717af287dc71f42a03b5cbce4","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/smb2ops.c"],"versions":[{"version":"5.1","status":"affected"},{"version":"0","lessThan":"5.1","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.7","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.1","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.1","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.1","versionEndExcluding":"7.2.7"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.1","versionEndExcluding":"7.3-rc2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/3673f057b64abfa957e8ae84448db69369a5091a"},{"url":"https://git.kernel.org/stable/c/06a4f9049cb6dc319bceec2dc813ba89add8b828"},{"url":"https://git.kernel.org/stable/c/f320ca20c273a26cd779bdb2b2e4b076a95c76f6"},{"url":"https://git.kernel.org/stable/c/88972e35750792e717af287dc71f42a03b5cbce4"}],"title":"smb/client: validate new EOF for zero range","x_generator":{"engine":"bippy-1.2.0"}}}}