Skip to main content
Vulnerability Database/CVE-2026-98125

CVE-2026-98125: Linux Kernel Information Disclosure Vulnerability

CVE-2026-98125 is an information disclosure flaw in the Linux kernel's SMB client that causes stale page cache data during insert/collapse range operations. This post explains its technical details, impact, and mitigation steps.

Published:

CVE-2026-98125 Overview

CVE-2026-98125 is a Linux kernel vulnerability in the SMB client that causes stale page cache data to be returned after smb3_insert_range() or smb3_collapse_range() operations. The affected functions call truncate_pagecache_range() to invalidate pages touched by fallocate insert and collapse range requests. When the offset or old end-of-file is not page-aligned, boundary pages remain marked uptodate with only partial zeroing. After the server completes the COPYCHUNK operation, subsequent reads from the client can return stale cached content instead of the data now stored on the server.

Critical Impact

Applications performing insert or collapse range operations over CIFS/SMB3 mounts can observe silent data corruption on read, returning stale cached bytes rather than the authoritative server-side data.

Affected Products

  • Linux kernel SMB/CIFS client (fs/smb/client)
  • Systems mounting remote shares using SMB3 with fallocate insert/collapse range support
  • Linux stable branches prior to the fix commits 01261a6 and 76222e7

Discovery Timeline

  • 2026-09-25 - CVE-2026-98125 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-98125

Vulnerability Analysis

The vulnerability resides in the SMB client implementations of smb3_insert_range() and smb3_collapse_range(). Both functions rely on truncate_pagecache_range() to drop cached pages covering the affected byte range before issuing the server-side COPYCHUNK request. The invalidation only fully evicts pages that are entirely within the range. Boundary pages that are partially inside the range are zeroed only for the overlapping bytes and left with their uptodate flag set. A subsequent read services the request from the stale page cache rather than fetching the newly rearranged data from the server.

The reproducer in the commit log uses a 6 KiB file on a CIFS mount, primes the page cache with a read, then invokes fallocate --insert-range -o 0 -l 4K. After the operation, the client returns the original data instead of the expected 4 KiB hole followed by the file contents.

Root Cause

The root cause is a kernel file system logic defect [CWE-logic] in page cache lifecycle handling. truncate_pagecache_range() is designed to discard whole pages inside a range and zero partial boundary pages, but it leaves those boundary pages marked uptodate. For insert and collapse range on SMB, where the server moves data outside the requested window, the uptodate boundary pages no longer reflect server state. The code assumed that partial zeroing of boundary pages was sufficient, which is only true when the file system itself updates in place.

Attack Vector

Exploitation requires local access to a mounted SMB3 share and the ability to issue fallocate insert or collapse range operations against a file whose offset or end-of-file is not page-aligned. The resulting condition is data integrity corruption rather than code execution or privilege escalation. Applications that depend on consistency between writes and subsequent reads over SMB can produce incorrect output, which may cascade into downstream integrity or availability issues depending on workload.

The fix, applied in commits 01261a6 and 76222e7, writes back dirty data and discards the page cache from the start of the page containing the offset through end-of-file before the server-side move.

Detection Methods for CVE-2026-98125

Indicators of Compromise

  • Applications on CIFS/SMB3 mounts reporting checksum mismatches or unexpected file contents after fallocate insert or collapse range calls.
  • Divergence between cat output from a CIFS client and the authoritative file content on the SMB server for recently rearranged files.
  • Kernel version strings on client hosts predating the Linux stable releases that include commits 01261a6 or 76222e7.

Detection Strategies

  • Inventory Linux hosts with CIFS/SMB3 mounts and compare running kernel versions against the stable branches that contain the fix.
  • Audit workloads for use of fallocate(FALLOC_FL_INSERT_RANGE) and fallocate(FALLOC_FL_COLLAPSE_RANGE) against files on SMB mounts, since these are the only triggers.
  • Add integrity checks (hashing, cmp) to data pipelines that modify SMB-hosted files via range operations to surface stale read conditions early.

Monitoring Recommendations

  • Enable auditd rules for fallocate syscalls on paths matching SMB mountpoints and correlate with application-level data validation failures.
  • Track kernel package versions across the fleet using existing configuration management telemetry.
  • Review SMB client /proc/fs/cifs/Stats counters for unusual COPYCHUNK activity on hosts running vulnerable kernels.

How to Mitigate CVE-2026-98125

Immediate Actions Required

  • Identify all Linux hosts mounting SMB3/CIFS shares and schedule kernel updates to a version containing the upstream fix.
  • Pause or guard workloads that call fallocate insert or collapse range on SMB-hosted files until the patch is applied.
  • Validate data integrity on files that may have been rearranged via fallocate on vulnerable clients.

Patch Information

The fix is applied in Linux kernel stable commits 01261a6 and 76222e7. The patched smb3_insert_range() and smb3_collapse_range() writeback dirty data and discard the page cache from the start of the page containing the offset through end-of-file before issuing the server-side move. Deploy distribution kernel updates that incorporate these commits.

Workarounds

  • Avoid using fallocate --insert-range and fallocate --collapse-range on files residing on SMB/CIFS mounts until patched kernels are deployed.
  • Drop the client page cache with echo 3 > /proc/sys/vm/drop_caches after range operations to force reads to go back to the server; this is a stop-gap and not a reliable fix.
  • Unmount and remount the SMB share after sensitive range operations to invalidate cached pages before applications read affected files.
bash
# Verify the running kernel includes the SMB client fix
uname -r

# Confirm whether any CIFS/SMB3 shares are mounted
mount -t cifs,smb3

# Short-term mitigation: drop page caches after a range operation
sync && echo 3 > /proc/sys/vm/drop_caches

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.