Description
In the Linux kernel, the following vulnerability has been resolved:

cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0

With len == 0 (clone to EOF), the effective length is computed as:

len = src_inode->i_size - off;

If off > i_size, this is a negative loff_t, corrupting the ByteCount
in the FSCTL_DUPLICATE_EXTENTS_TO_FILE request and inverting the range
in filemap_write_and_wait_range(). The existing off >= i_size check
fires only after the ioctl has already been sent.

Snapshot i_size_read() once for both the bounds check and the length
calculation, eliminating the TOCTOU and 32-bit torn-read risk. Reject
off > src_size with -EINVAL. Treat off == src_size as a no-op,
consistent with __generic_remap_file_range_prep().
Published: 2026-09-11
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service / Write Corruption
Action: Immediate Patch
AI Analysis

Impact

Based on the description, it is inferred that The Linux kernel’s CIFS server implements a remap operation that copies ranges of a file. When the length argument of this remap call is zero, the’s size minus the supplied offset. If the offset is larger than the file size, that subtraction yields a negative loff_t value. This under‑flow corrupts the ByteCount field in the FSCTL_DUPLICATE_EXTENTS_TO_FILE ioctl and can reverse the write range in the kernel’s filemap_write_and_wait_range routine, potentially leading The flaw is a classic integer under‑flow bug (CWE‑787), which can compromise the integrity and availability of files served via CIFS.

Affected Systems

The vulnerability is present in all Linux kernel releases that include the CIFS server module before the commit that adds the bounds check and rejects offsets larger than the source size. Systems running those kernel versions and exposing CIFS/SMB services are affected. The fix is included in the commit referenced in the advisory; kernel maintainers have integrated it into recent releases. Vendor‑compiled kernels that have not applied this change remain vulnerable.

Risk and Exploitability

The CVSS score of 7.1 denotes high severity. The EPSS score is less than 1%, indicating a low probability of exploitation in the wild. The flaw is not reported in the CISA KEV catalog. The likely attack vector is remote network access to a CIFS server, with an attacker sending an FSCTL_DUPLICATE_EXTENTS_TO_FILE ioctl with a zero‑length request and an offset exceeding the source file size. No special privileges are required on the client side, so local privilege escalation is not needed. The attack would cause either corruption of file metadata or a denial of service for the CIFS service.

Generated by OpenCVE AI on September 15, 2026 at 21:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that includes the commit that adds the offset bounds check and rejects off > src_size.
  • If a kernel update is not possible, disable CIFS/SMB services or restrict network access to them using firewall rules.
  • Monitor system logs for kernel messages related to CIFS and FSCTL_DUPLICATE_EXTENTS_TO_FILE activities to detect attempted exploitation; consider enabling audit logging for SMB ioctl requests.

Generated by OpenCVE AI on September 15, 2026 at 21:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H'}

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Sat, 12 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H'}

threat_severity

Important


Sat, 12 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0 With len == 0 (clone to EOF), the effective length is computed as: len = src_inode->i_size - off; If off > i_size, this is a negative loff_t, corrupting the ByteCount in the FSCTL_DUPLICATE_EXTENTS_TO_FILE request and inverting the range in filemap_write_and_wait_range(). The existing off >= i_size check fires only after the ioctl has already been sent. Snapshot i_size_read() once for both the bounds check and the length calculation, eliminating the TOCTOU and 32-bit torn-read risk. Reject off > src_size with -EINVAL. Treat off == src_size as a no-op, consistent with __generic_remap_file_range_prep().
Title cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:01:42.820Z

Reserved: 2026-09-11T19:38:34.740Z

Link: CVE-2026-89640

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:49.733

Modified: 2026-09-14T13:19:16.940

Link: CVE-2026-89640

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:45:33Z

Links: CVE-2026-89640 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:30:16Z

Weaknesses