Impact
The Linux kernel contains a flaw in the CIFS filesystem driver where the function cifs_setsize() calls truncate_pagecache() but does not invoke page expanded of the page that crosses the old end‑of‑file remains uncleared, so dirty bytes that are no longer part of the logical file size can be written back to the CIFS server CWE‑201: Improper Restriction of Operations within the Bounds of a Resource. If an attacker can create or grow a file on a CIFS mount, these stale bytes may be flushed to the server and later read from the server side, exposing data that should no longer exist in the file.
Affected Systems
Any Linux system running a adding the missing pagecache_isize_extended() call in cifs_setsize(), while the CIFS filesystem is enabled. Systems that mount CIFS shares from Windows or Samba servers and can write to the share are potentially affected. This includes standard Linux distributions that ship the Linux kernel older than the fix.
Risk and Exploitability
The base CVSS score is 6.5, indicating medium severity. The EPSS score is less than 1%, indicating a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires write access to a CIFS‑mounted file and the existence of dirty pages that contain stale data beyond the logical file size. An attacker would need to extend a file to trigger the write of stale bytes and then read the server copy of the file to recover the leaked data. While no public exploits are available, the combination of a medium intensity flaw and the need for specific conditions makes the risk moderate but not trivial.
OpenCVE Enrichment