CVE-2026-98124 Overview
CVE-2026-98124 is a cache coherency flaw in the Linux kernel's SMB client. The smb3_zero_range(), smb3_punch_hole(), smb3_insert_range(), and smb3_collapse_range() functions modify file contents through server-side range operations. These operations discard the affected page cache but leave the FS-Cache cookie valid. A later read may return data cached before the range operation, exposing stale file content.
The issue affects CIFS mounts with FS-Cache (fsc) enabled and an active CacheFiles backend. The resolved fix invalidates FS-Cache after outstanding I/O completes and before modifying the file on the server.
Critical Impact
Applications reading from CIFS mounts with FS-Cache enabled can receive stale data after fallocate range operations, leading to data integrity failures and potential information disclosure.
Affected Products
- Linux kernel SMB/CIFS client (fs/smb/client)
- Systems with FS-Cache (fsc mount option) enabled on CIFS mounts
- Deployments using CacheFiles backend with SMB shares
Discovery Timeline
- 2026-09-25 - CVE-2026-98124 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-98124
Vulnerability Analysis
The Linux SMB client exposes four fallocate range operations that mutate file contents on the server: zero-range, punch-hole, insert-range, and collapse-range. Each operation drops the affected page cache after completion. However, the FS-Cache cookie associated with the file remains valid and continues to reference pre-modification data.
When an application subsequently reads from the modified range, the kernel satisfies the request from FS-Cache rather than issuing a network read. The returned data reflects the file state before the range operation, not the current server state. The reproducer in the fix commit demonstrates this: a fallocate --zero-range on an offset backed by cached data returns the original random bytes instead of zeros.
The fix invalidates the FS-Cache cookie at two points. First, after any outstanding I/O completes to prevent racing writes from repopulating stale entries. Second, before the server-side range modification is issued, ensuring subsequent reads miss the local cache and fetch authoritative data from the server.
Root Cause
The root cause is incomplete cache invalidation in the SMB client fallocate path. Page cache invalidation was performed, but the FS-Cache layer was not notified that cached blocks were no longer valid. The two cache layers held inconsistent views of file contents.
Attack Vector
The vulnerability is a data integrity defect rather than a direct remote exploit. Any local process reading a CIFS-mounted file after a fallocate range operation can observe stale data. Workloads that depend on read-after-write consistency, such as databases, backup software, or build systems operating on network shares, can produce incorrect results. The condition requires FS-Cache to be enabled on the mount.
The vulnerability manifests in the SMB fallocate handlers. See the referenced upstream commits for the exact code path.
Detection Methods for CVE-2026-98124
Indicators of Compromise
- Unexpected mismatch between file contents observed by applications and the authoritative content on the SMB server
- cmp or checksum failures on files recently modified with fallocate operations against CIFS mounts with fsc enabled
- Application-level data corruption reports from workloads using CIFS shares with CacheFiles active
Detection Strategies
- Enumerate mounted CIFS filesystems and identify those using the fsc mount option by inspecting /proc/mounts and mount unit configurations
- Correlate kernel version data from endpoint inventory against the fixed commits 448ba0ae and 93c6e5a8 to identify unpatched hosts
- Run the reproducer from the upstream commit in a controlled environment to confirm whether a given kernel exhibits the stale-read behavior
Monitoring Recommendations
- Monitor cachefilesd activity and FS-Cache statistics in /proc/fs/fscache/stats for workloads that perform fallocate operations
- Track kernel package versions across the fleet and alert when CIFS clients run kernels predating the fix
- Log application-reported file integrity errors from systems with CIFS mounts to catch stale-read incidents
How to Mitigate CVE-2026-98124
Immediate Actions Required
- Identify all Linux hosts with CIFS mounts configured with the fsc mount option and prioritize them for patching
- Apply the upstream kernel fix referenced in commits 448ba0ae65ca and 93c6e5a8d7c5 or the vendor-backported equivalent
- Validate the fix by executing the reproducer from the commit message against a test share
Patch Information
The fix is upstream in the Linux kernel as two commits: Linux Kernel Commit 448ba0ae and Linux Kernel Commit 93c6e5a8. Distribution kernels require backports; consult your vendor's security advisories for the specific package versions containing the fix.
Workarounds
- Remount affected CIFS shares without the fsc option to disable FS-Cache until the kernel is patched
- Stop and disable cachefilesd on hosts where FS-Cache cannot be removed from mount options immediately
- Avoid fallocate range operations (--zero-range, --punch-hole, --insert-range, --collapse-range) on cached CIFS files until the fix is deployed
# Remount CIFS shares without FS-Cache as a temporary workaround
mount -o remount,nofsc /mnt/cifs
# Verify the fsc option is no longer present
grep cifs /proc/mounts
# Disable the CacheFiles daemon fleet-wide if not required
systemctl stop cachefilesd
systemctl disable cachefilesd
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.