CVE-2026-98127: smb/client: validate new EOF for insert range

Published Sep 25, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

smb/client: validate new EOF for insert range

smb3insertrange() does not check if the new file size (isize + len) is valid. This allows FALLOCFLINSERTRANGE to bypass RLIMITFSIZE, exceed smaxbytes, or produce a size outside the lofft range.

Use checkaddoverflow() to calculate the new EOF. Validate it with inodenewsizeok() before modifying the file.

Reproducer, using a file on a CIFS mount:

bash -c ' FILE=/mnt/cifs/repro

trap "" SIGXFSZ ulimit -f 3072 # RLIMITFSIZE = 3 MiB

# A regular write is stopped at 3 MiB. dd if=/dev/zero of="$FILE" bs=1M count=4 status=none stat -c "size after write: %s" "$FILE"

# Insert 2 MiB into a 2 MiB file. truncate -s 2M "$FILE" fallocate -i -o 0 -l 2M "$FILE" stat -c "size after insert: %s" "$FILE" '

Before this change, the regular write stops at the 3 MiB limit, but insert range grows the file to 4 MiB:

dd: error writing '/mnt/cifs/repro': File too large size after write: 3145728 size after insert: 4194304

After this change, insert range also fails at the limit and leaves the 2 MiB file unchanged:

dd: error writing '/mnt/cifs/repro': File too large size after write: 3145728 fallocate: fallocate failed: File too large size after insert: 2097152

Affected Software

1 affected component
Linux Linux kernel

Event History

Sep 25, 2026
CVE Published
via MITRE·10:36 AM
Data Sourced
via MITRE·10:36 AM
Description

Frequently Asked Questions

1

Who is affected by this issue?

Systems using the Linux kernel SMB/CIFS client with files on a CIFS mount are affected when an application uses the FALLOC_FL_INSERT_RANGE operation. The issue concerns growth of a file through insert-range allocation rather than ordinary writes.

2

What does an attacker or local user need to do to trigger it?

They need to perform an insert-range fallocate operation on a file located on a CIFS mount. By choosing a range that increases the file size, they can bypass RLIMIT_FSIZE checks and potentially exceed the filesystem maximum size or loff_t range.

3

How can I determine whether a system is vulnerable?

On a CIFS-mounted file, set a restrictive RLIMIT_FSIZE, create or truncate a file below that limit, then use fallocate with insert range to grow it. A vulnerable kernel permits the insert operation to grow the file beyond the limit; the fixed behavior rejects it and leaves the file unchanged.

4

What happens after the fix?

The kernel calculates the new end-of-file with overflow checking and validates the proposed size before modifying the file. Insert-range operations that would exceed the allowed size fail instead of extending the file.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203