Impact
Based on the description, it is inferred that The Linux kernel’s CIFS server implements a remap operation that copies ranges of a file. When the length argument of this remap call is zero, the’s size minus the supplied offset. If the offset is larger than the file size, that subtraction yields a negative loff_t value. This under‑flow corrupts the ByteCount field in the FSCTL_DUPLICATE_EXTENTS_TO_FILE ioctl and can reverse the write range in the kernel’s filemap_write_and_wait_range routine, potentially leading The flaw is a classic integer under‑flow bug (CWE‑787), which can compromise the integrity and availability of files served via CIFS.
Affected Systems
The vulnerability is present in all Linux kernel releases that include the CIFS server module before the commit that adds the bounds check and rejects offsets larger than the source size. Systems running those kernel versions and exposing CIFS/SMB services are affected. The fix is included in the commit referenced in the advisory; kernel maintainers have integrated it into recent releases. Vendor‑compiled kernels that have not applied this change remain vulnerable.
Risk and Exploitability
The CVSS score of 7.1 denotes high severity. The EPSS score is less than 1%, indicating a low probability of exploitation in the wild. The flaw is not reported in the CISA KEV catalog. The likely attack vector is remote network access to a CIFS server, with an attacker sending an FSCTL_DUPLICATE_EXTENTS_TO_FILE ioctl with a zero‑length request and an offset exceeding the source file size. No special privileges are required on the client side, so local privilege escalation is not needed. The attack would cause either corruption of file metadata or a denial of service for the CIFS service.
OpenCVE Enrichment
Debian DSA