Impact
The vulnerability resides in the Linux kernel's CIFS client share is truncated to zero length. During this operation the kernel fails to invalidate the file's cache, allowing stale cached data to remain available. Consequently, a reader of the file after truncation can receive data that were present before the truncate, exposing sensitive information that should no longer exist.
Affected Systems
All Linux kernel installations that compile the in‑tree CIFS client are affected. This includes the default CIFS support shipped by major distributions and any custom kernel using the same module. Any machine that mounts SMB/CIFS shares with the default caching enabled is at risk, regardless of the filesystem’s local ownership or the operating system vendor.
Risk and Exploitability
The flaw provides an information‑disclosure risk but does not grant privilege escalation or remote execution. An attacker must be able to truncate a file on a shared CIFS volume, a capability available to ordinary users who have write permissions on the share. The EPSS score of less than 1% indicates low likelihood of current exploitation, yet the CVSS score of 7.1 reflects high severity. The issue is not listed in the CISA KEV catalog, and no remote exploitation vectors are documented. The risk is therefore moderate for environments that enable caching and provide write access to untrusted users.
OpenCVE Enrichment