CVE-2026-98127: smb/client: validate new EOF for insert range
In the Linux kernel, the following vulnerability has been resolved:
smb/client: validate new EOF for insert range
smb3insertrange() does not check if the new file size (isize + len) is valid. This allows FALLOCFLINSERTRANGE to bypass RLIMITFSIZE, exceed smaxbytes, or produce a size outside the lofft range.
Use checkaddoverflow() to calculate the new EOF. Validate it with inodenewsizeok() before modifying the file.
Reproducer, using a file on a CIFS mount:
bash -c ' FILE=/mnt/cifs/repro
trap "" SIGXFSZ ulimit -f 3072 # RLIMITFSIZE = 3 MiB
# A regular write is stopped at 3 MiB. dd if=/dev/zero of="$FILE" bs=1M count=4 status=none stat -c "size after write: %s" "$FILE"
# Insert 2 MiB into a 2 MiB file. truncate -s 2M "$FILE" fallocate -i -o 0 -l 2M "$FILE" stat -c "size after insert: %s" "$FILE" '
Before this change, the regular write stops at the 3 MiB limit, but insert range grows the file to 4 MiB:
dd: error writing '/mnt/cifs/repro': File too large size after write: 3145728 size after insert: 4194304
After this change, insert range also fails at the limit and leaves the 2 MiB file unchanged:
dd: error writing '/mnt/cifs/repro': File too large size after write: 3145728 fallocate: fallocate failed: File too large size after insert: 2097152
Affected Software
Event History
Frequently Asked Questions
Who is affected by this issue?
Systems using the Linux kernel SMB/CIFS client with files on a CIFS mount are affected when an application uses the FALLOC_FL_INSERT_RANGE operation. The issue concerns growth of a file through insert-range allocation rather than ordinary writes.
What does an attacker or local user need to do to trigger it?
They need to perform an insert-range fallocate operation on a file located on a CIFS mount. By choosing a range that increases the file size, they can bypass RLIMIT_FSIZE checks and potentially exceed the filesystem maximum size or loff_t range.
How can I determine whether a system is vulnerable?
On a CIFS-mounted file, set a restrictive RLIMIT_FSIZE, create or truncate a file below that limit, then use fallocate with insert range to grow it. A vulnerable kernel permits the insert operation to grow the file beyond the limit; the fixed behavior rejects it and leaves the file unchanged.
What happens after the fix?
The kernel calculates the new end-of-file with overflow checking and validates the proposed size before modifying the file. Insert-range operations that would exceed the allowed size fail instead of extending the file.