Description
In the Linux kernel, the following vulnerability has been resolved:

cifs: call pagecache_isize_extended() in cifs_setsize() when extending

cifs_setsize() calls truncate_pagecache() but skips
pagecache_isize_extended() on extension. truncate_setsize() shows
the correct pattern:

i_size_write(inode, newsize);
if (newsize > oldsize)
pagecache_isize_extended(inode, oldsize, newsize);
truncate_pagecache(inode, newsize);

pagecache_isize_extended() zeroes the tail of the page straddling old
EOF. Without it, dirty bytes in that region can be written back to
the server, exposing stale data in the newly extended range.
Published: 2026-09-11
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure via stale data leakage when CIFS files are extended
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel contains a flaw in the CIFS filesystem driver where the function cifs_setsize() calls truncate_pagecache() but does not invoke page expanded of the page that crosses the old end‑of‑file remains uncleared, so dirty bytes that are no longer part of the logical file size can be written back to the CIFS server CWE‑201: Improper Restriction of Operations within the Bounds of a Resource. If an attacker can create or grow a file on a CIFS mount, these stale bytes may be flushed to the server and later read from the server side, exposing data that should no longer exist in the file.

Affected Systems

Any Linux system running a adding the missing pagecache_isize_extended() call in cifs_setsize(), while the CIFS filesystem is enabled. Systems that mount CIFS shares from Windows or Samba servers and can write to the share are potentially affected. This includes standard Linux distributions that ship the Linux kernel older than the fix.

Risk and Exploitability

The base CVSS score is 6.5, indicating medium severity. The EPSS score is less than 1%, indicating a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires write access to a CIFS‑mounted file and the existence of dirty pages that contain stale data beyond the logical file size. An attacker would need to extend a file to trigger the write of stale bytes and then read the server copy of the file to recover the leaked data. While no public exploits are available, the combination of a medium intensity flaw and the need for specific conditions makes the risk moderate but not trivial.

Generated by OpenCVE AI on September 15, 2026 at 21:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the missing pagecache_isize_extended() call during file size extensions.
  • Verify that CIFS mounts use the updated kernel and do not employ legacy mount options that could bypass or modify the fix.
  • If an upgrade cannot be performed immediately, restrict write access to CIFS shares to trusted users and consider clearing or flushing dirty pages on the server side to prevent stale data leakage.

Generated by OpenCVE AI on September 15, 2026 at 21:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-201
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: cifs: call pagecache_isize_extended() in cifs_setsize() when extending cifs_setsize() calls truncate_pagecache() but skips pagecache_isize_extended() on extension. truncate_setsize() shows the correct pattern: i_size_write(inode, newsize); if (newsize > oldsize) pagecache_isize_extended(inode, oldsize, newsize); truncate_pagecache(inode, newsize); pagecache_isize_extended() zeroes the tail of the page straddling old EOF. Without it, dirty bytes in that region can be written back to the server, exposing stale data in the newly extended range.
Title cifs: call pagecache_isize_extended() in cifs_setsize() when extending
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:24:05.607Z

Reserved: 2026-09-11T19:38:34.741Z

Link: CVE-2026-89642

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:49.980

Modified: 2026-09-13T07:17:29.493

Link: CVE-2026-89642

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:45:34Z

Links: CVE-2026-89642 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:15:14Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data